Re: Stumped @ MySql insert query

From: Date: Fri, 13 Jun 2003 18:42:23 +0000
Subject: Re: Stumped @ MySql insert query
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-151401@lists.php.net to get a copy of this message
On Friday, June 13, 2003, at 02:22 PM, Zak Johnson wrote:
$_POST variables are still subject to poisoning; in your case, SQL injection.
How is variable poisoning possible when using $_POST ?? I always felt that the php compiler should check to see if the variable was part of the POST Global array. At least this is is what I thought about the $_POST global array. Thanks in advance --Pushpinder

« previous php.general (#151401) next »