Re: Weird Wildcard Search
| From: | Manuel | Date: | Fri, 13 Oct 2000 14:11:36 +0000 |
| Subject: | Re: Weird Wildcard Search | ||
| Groups: | php.db | ||
| Request: | Send a blank email to php-db+get-3589@lists.php.net to get a copy of this message | ||
Hi Lutz,
Thanks for your suggestions.
I am using the combination of urlencode/urldecode and addslashes/stripslashes.
echo " <a href=\"sresults.php3?sqlstmt=$sqlstmt&CR=$CR&RL=$y\">[Next]</a>"; Doing $sqlstmt = urlencode($sqlstmt) befor this echo protects the variable in the url.Other user pointed out a potential danger... some clown putting DELETE * FROM TABLE in the SQL stmt. Anyway, I have changed it to pass only the variable. It was never my intention to have a full SQL stmt. I was trying to find a solution and was hoping by echoing the full SQL stmt will give me a better picture. Phew.. if I have implemented it with the SQLstmt then I will be in BIG trouble... :):) Thanks guys...