False Positive SQL Injection
-
Does WordFence block any SQL query it detects? I’ve been able to trigger a 403 using this href, /wp-admin/admin-ajax.php?test=UNION%20ALL%20SELECT%20NULL,NULL,NULL,NULL,NULL,NULL# (it doesn’t actually do anything. try it on a site with WordFence installed).
The reason I’m asking is because I received an email telling me WordFence has blocked 130 SQL Injection attacks. But I’m pretty sure they’re all false positives.
Viewing 4 replies - 1 through 4 (of 4 total)
Viewing 4 replies - 1 through 4 (of 4 total)
The topic ‘False Positive SQL Injection’ is closed to new replies.