Re: Stumped @ MySql insert query
| From: | Pushpinder Singh Garcha | Date: | Fri, 13 Jun 2003 18:42:23 +0000 |
| Subject: | Re: Stumped @ MySql insert query | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-151401@lists.php.net to get a copy of this message | ||
On Friday, June 13, 2003, at 02:22 PM, Zak Johnson wrote:
$_POST variables are still subject to poisoning; in your case, SQL injection.How is variable poisoning possible when using $_POST ?? I always felt that the php compiler should check to see if the variable was part of the POST Global array. At least this is is what I thought about the $_POST global array. Thanks in advance --Pushpinder