RE: [PHP] Security alert and question: semicolon taint
| From: | Jason Murray | Date: | Mon, 04 Sep 2000 05:57:02 +0000 |
| Subject: | RE: [PHP] Security alert and question: semicolon taint | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-15051@lists.php.net to get a copy of this message | ||
> Yes, you will get SQL errors if you feed the DB a quoted
> string when it is expecting a number.
MySQL at least doesn't have a problem with using quotes here:
"select * from table where <<int-field>> =
'<<int-value>>'"
Jason