Re: Serialised Data & DBs

From: Date: Tue, 30 Jul 2002 21:23:50 +0000
Subject: Re: Serialised Data & DBs
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-110421@lists.php.net to get a copy of this message
----- Original Message ----- From: "1LT John W. Holmes" <holmes072000@charter.net> To: "Danny Shepherd" <danny@kyboshed.com>; "PHP-General" <php-general@lists.php.net> Sent: Tuesday, July 30, 2002 8:18 PM Subject: Re: [PHP] Serialised Data & DBs > Yes, it'd be really smart to. If any of the data in the serialized string > has a ' or " in it, it could break your query. Or the user being able to > enter a ' or " into the data could open you to SQL attacks. > > You want to do addslashes() on the result of serialize(), not the content > going into it, too. PHP will introduct double quotes around any strings that > are serialized. These should be escaped or they could end up breaking your > query. Yeah, the contents are already stripslashed. > Note that you don't have to do stripslashes() on the serialized string when > you pull it out. Cool, didn't realise that - would've been hard to track down later too! Thanks, Danny.

« previous php.general (#110421) next »