Re: Serialised Data & DBs

From: Date: Tue, 30 Jul 2002 19:18:05 +0000
Subject: Re: Serialised Data & DBs
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-110401@lists.php.net to get a copy of this message
Yes, it'd be really smart to. If any of the data in the serialized string has a ' or " in it, it could break your query. Or the user being able to enter a ' or " into the data could open you to SQL attacks. You want to do addslashes() on the result of serialize(), not the content going into it, too. PHP will introduct double quotes around any strings that are serialized. These should be escaped or they could end up breaking your query. Note that you don't have to do stripslashes() on the serialized string when you pull it out. ---John Holmes... ----- Original Message ----- From: "Danny Shepherd" <danny@kyboshed.com> To: "PHP-General" <php-general@lists.php.net> Sent: Tuesday, July 30, 2002 2:56 PM Subject: [PHP] Serialised Data & DBs > Hi, > > Is it necessary to perform addslashes() on serialised data before inserting > it into a database? > > Thanks, > > Danny. > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, visit: http://www.php.net/unsub.php >

« previous php.general (#110401) next »