Re: UPDATE mysql

From: Date: Sun, 23 Jun 2002 04:14:23 +0000
Subject: Re: UPDATE mysql
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-103442@lists.php.net to get a copy of this message
> $query = "UPDATE $table SET field1='$var1' WHERE id='$id'"; I really hope you don't have register_globals on, or you are validating the value of $table before you run this kind of query, otherwise your query is open up to an attack to update any table in the database... $table = "admin SET admin='Yes' WHERE username='John' #"; The # will make the remainder of your query a comment and it'll be ignored by MySQL... ---John Holmes...

« previous php.general (#103442) next »