Re: Weird Wildcard Search

From: Date: Fri, 13 Oct 2000 14:11:36 +0000
Subject: Re: Weird Wildcard Search
Groups: php.db 
Request: Send a blank email to php-db+get-3589@lists.php.net to get a copy of this message
Hi Lutz, Thanks for your suggestions. I am using the combination of urlencode/urldecode and addslashes/stripslashes.
echo " <a href=\"sresults.php3?sqlstmt=$sqlstmt&CR=$CR&RL=$y\">[Next]</a>"; Doing $sqlstmt = urlencode($sqlstmt) befor this echo protects the variable in the url.
Other user pointed out a potential danger... some clown putting DELETE * FROM TABLE in the SQL stmt. Anyway, I have changed it to pass only the variable. It was never my intention to have a full SQL stmt. I was trying to find a solution and was hoping by echoing the full SQL stmt will give me a better picture. Phew.. if I have implemented it with the SQLstmt then I will be in BIG trouble... :):) Thanks guys...

« previous php.db (#3589) next »