RE: [PHP] extract($_POST)

From: Date: Mon, 28 Oct 2002 13:03:01 +0000
Subject: RE: [PHP] extract($_POST)
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-121690@lists.php.net to get a copy of this message
[snip] Lets say you have a statement like: $query = "SELECT * FROM mytable WHERE firstname=$firstname"; And if $firstname is set to: "xyz"; DELETE FROM mytable Then this is executed as: SELECT* FROM mytable WHERE firstname="xyz";DELETE FROM mytable This can wipe out your table...a bad thing... [/snip] Ah! But only if the database user has permissions for DELETE. That is why security must be carefully thought out, because there are so many levels for it to be implemented on. This has been a great thread, lots of useful information. Jay

« previous php.general (#121690) next »