← Back to context

Comment by baybal2

6 years ago

I wonder, what will "DROP *;" license plate do?

Nah, because it's not unsanitized SQL at fault, but people writing a literal NULL in the license plate field when there isn't one.

Should be

    "; DROP *;

Lic. plates are entered into thousands of systems, so yeah it can have an effect somewhere.

Most states do not allow special characters in the plate text.

  • Depends on how you define "special." I've seen hearts on California tags, and I think some glyphs on Virginia tags, but I might not be remembering that correctly.

    • That's just part of the design. They are ignored when you type it in, etc. and you can't have ABC<heart>123 and ABC123 simultaneously existing because they're the same to the DMV.