SQL Sanitation in PHP
| From: | Jeff Stewart | Date: | Fri, 20 Jun 2003 17:13:28 +0000 |
| Subject: | SQL Sanitation in PHP | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-152324@lists.php.net to get a copy of this message | ||
I'm using PHP's odbc_ functions to access an Access database, and I'm
concerned about security. Do you folks have any recommendations on the best
ways to sanitize my SQL queries?
I've read plenty about what characters I should strip from SQL queries that
use user input, namely " , / \ * & ( ) $ % ^ @ ~ ´ ?
Does PHP require anything more?
--
Jeff S.