<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>SQL on Omid Farhang</title><link>https://omid.dev/tags/sql/</link><description>Recent content in SQL on Omid Farhang</description><image><title>Omid Farhang</title><url>https://omid.dev/images/bio-photo-150x150.jpg</url><link>https://omid.dev/images/bio-photo-150x150.jpg</link></image><generator>Hugo -- 0.163.3</generator><language>en-US</language><copyright>2026 Omid Farhang | All rights reserved.</copyright><lastBuildDate>Sun, 19 Aug 2012 08:51:00 +0000</lastBuildDate><atom:link href="https://omid.dev/tags/sql/index.xml" rel="self" type="application/rss+xml"/><item><title>PostgreSQL patches XML flaws</title><link>https://omid.dev/2012/08/19/postgresql-patches-xml-flaws/</link><pubDate>Sun, 19 Aug 2012 08:51:00 +0000</pubDate><guid>https://omid.dev/2012/08/19/postgresql-patches-xml-flaws/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="http://lh5.ggpht.com/-_CvERcVioNM/UDCiAjUuQUI/AAAAAAAAG_k/BhHqmScL6wQ/s1600-h/PostgreSQL_Logo%25255B2%25255D.png" alt="PostgreSQL_Logo" /&gt;
&lt;/p&gt;
&lt;p&gt;h-online: A flaw in the built-in XML functionality of &lt;a href="http://www.postgresql.org/"&gt;PostgreSQL&lt;/a&gt; (CVE-2012-3488) and another in its optional XSLT handling (CVE-2012-3489) have been patched, and the developers have &lt;a href="http://www.postgresql.org/about/news/1407/"&gt;released updated versions&lt;/a&gt; of the open source database with relevant fixes. The holes being patched are related to insecure use of the widely used libxml2 and libxslt open source libraries and the PostgreSQL developers advise anyone using those libraries to check their systems for similar problems.&lt;/p&gt;</description></item><item><title>Massive SQL injection attack making the rounds—694K URLs so far</title><link>https://omid.dev/2011/04/01/massive-sql-injection-attack-making-the-rounds-694k-urls-so-far/</link><pubDate>Fri, 01 Apr 2011 22:23:00 +0000</pubDate><guid>https://omid.dev/2011/04/01/massive-sql-injection-attack-making-the-rounds-694k-urls-so-far/</guid><description>&lt;p&gt;&lt;strong&gt;&lt;img loading="lazy" src="http://lh5.ggpht.com/_vaUVXcmC3OI/TZZJJOzqeiI/AAAAAAAADzY/FcnGCJKWL3Y/s1600-h/sql_img%5B4%5D.jpg" alt="sql_img" /&gt;
&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Thanks to my friend, Pondus!&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Ars Technica:&lt;/strong&gt; Hundreds of thousands of URLs have been compromised—at the time of writing, 694,000 (it’s over millions of site when you are reading this)—in an enormous and indiscriminate SQL injection attack. The attack has modified text stored in databases, with the result that pages served up by the attacked systems include within each page one or more references to a particular JavaScript file.&lt;/p&gt;</description></item></channel></rss>