<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic REST where clause and SQL Injection in ArcGIS REST APIs and Services Questions</title>
    <link>https://community.esri.com/t5/arcgis-rest-apis-and-services-questions/rest-where-clause-and-sql-injection/m-p/406722#M1978</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I'm trying to determine how safe it is to publish REST services for mash-up consumption. Specifically I am wondering if the WHERE clause for querying is vulnerable to any kind of SQL Injection attack?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks in advance!&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 17 Dec 2010 13:28:09 GMT</pubDate>
    <dc:creator>JonathanBaier</dc:creator>
    <dc:date>2010-12-17T13:28:09Z</dc:date>
    <item>
      <title>REST where clause and SQL Injection</title>
      <link>https://community.esri.com/t5/arcgis-rest-apis-and-services-questions/rest-where-clause-and-sql-injection/m-p/406722#M1978</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I'm trying to determine how safe it is to publish REST services for mash-up consumption. Specifically I am wondering if the WHERE clause for querying is vulnerable to any kind of SQL Injection attack?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks in advance!&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Dec 2010 13:28:09 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-rest-apis-and-services-questions/rest-where-clause-and-sql-injection/m-p/406722#M1978</guid>
      <dc:creator>JonathanBaier</dc:creator>
      <dc:date>2010-12-17T13:28:09Z</dc:date>
    </item>
    <item>
      <title>Re: REST where clause and SQL Injection</title>
      <link>https://community.esri.com/t5/arcgis-rest-apis-and-services-questions/rest-where-clause-and-sql-injection/m-p/406723#M1979</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;There are the patches on sql injection: &lt;/SPAN&gt;&lt;A href="http://support.esri.com/zh-cn/knowledgebase/techarticles/detail/40677"&gt;http://support.esri.com/zh-cn/knowledgebase/techarticles/detail/40677&lt;/A&gt;&lt;SPAN&gt; . &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;However I advise use ags 10.2 or superior why ArcGIS Server includes a security option that forces developers to use standardized SQL queries (for details: &lt;/SPAN&gt;&lt;A href="http://resources.arcgis.com/en/help/main/10.2/index.html#//015400000641000000"&gt;http://resources.arcgis.com/en/help/main/10.2/index.html#//015400000641000000&lt;/A&gt;&lt;SPAN&gt; )&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Feb 2014 09:37:35 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-rest-apis-and-services-questions/rest-where-clause-and-sql-injection/m-p/406723#M1979</guid>
      <dc:creator>nicogis</dc:creator>
      <dc:date>2014-02-21T09:37:35Z</dc:date>
    </item>
  </channel>
</rss>

