Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Running ad hoc sql queries - security issueRunning ad hoc sql queries - security issue
Previous
 
Next
New Post
12/15/2008 12:40 PM
 

Of the modules which come with DNN, is there any way a user can run an ad hoc sql query? I downloaded a free module called SQL View from some site and I didn't like the fact the user was able to query any table, which was a security issue for me.

I wanted to me sure none of the pre installed modules give them the same ability.

 

 
New Post
12/15/2008 1:41 PM
 
the reports module allows users to run sql queries, however, they can only be setup by host users. Also Host>SQL allows you to run an sql query... also host only though

Erik van Ballegoij, Former DNN Corp. Employee and DNN Expert

DNN Blog | Twitter: @erikvb | LinkedIn: Erik van Ballegoij on LinkedIn

 
New Post
12/15/2008 4:29 PM
 

Salama wrote

Of the modules which come with DNN, is there any way a user can run an ad hoc sql query? I downloaded a free module called SQL View from some site and I didn't like the fact the user was able to query any table, which was a security issue for me.

I wanted to me sure none of the pre installed modules give them the same ability.

 

SQl view is configurable - you can restrict it as you please.  It's the same as making any user a SuperUser - you can give any user ultimate power, but it's up to you to restrict the permissions and chose who can use it so that they cannot do harm.


Entrepreneur

PokerDIY Tournament Manager - PokerDIY Tournament Manager<
PokerDIY Game Finder - Mobile Apps powered by DNN
PokerDIY - Connecting Poker Players

 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Running ad hoc sql queries - security issueRunning ad hoc sql queries - security issue


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out