RE: [PHP] Security alert and question: semicolon taint
| From: | Rasmus Lerdorf | Date: | Mon, 04 Sep 2000 04:54:56 +0000 |
| Subject: | RE: [PHP] Security alert and question: semicolon taint | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-15050@lists.php.net to get a copy of this message | ||
> Do you see a problem with just wrapping all the values in the query with
> quotes? That would seem like the simple way to do it. But I'll probably go
> back and error check the tainted values anyway. Speaking of which, does PHP
> have some sort of taint checking like Perl?
Yes, you will get SQL errors if you feed the DB a quoted string when it is
expecting a number.
-Rasmus