Re: UPDATE mysql
| From: | 1LT John W. Holmes | Date: | Sun, 23 Jun 2002 04:14:23 +0000 |
| Subject: | Re: UPDATE mysql | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-103442@lists.php.net to get a copy of this message | ||
> $query = "UPDATE $table SET field1='$var1' WHERE id='$id'";
I really hope you don't have register_globals on, or you are validating the
value of $table before you run this kind of query, otherwise your query is
open up to an attack to update any table in the database...
$table = "admin SET admin='Yes' WHERE username='John' #";
The # will make the remainder of your query a comment and it'll be ignored
by MySQL...
---John Holmes...