RE: [PHP] SQL security
| From: | Chris Shiflett | Date: | Fri, 17 Oct 2003 16:14:57 +0000 |
| Subject: | RE: [PHP] SQL security | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-166488@lists.php.net to get a copy of this message | ||
--- "Chris W. Parker" <cparker@swatgear.com> wrote:
> Doesn't MySQL automatically protect against attacks like SQL
> injection? Or maybe it's that it automatically applies addslashes()?
Nope and nope.
What you might be thinking of is that mysql_query() only allows a single query
to be executed. This helps, but it doesn't prevent everything. It only prevents
SQL injection attacks that attempt to terminate the current query and execute
another one.
Chris
=====
My Blog
http://shiflett.org/
HTTP Developer's Handbook
http://httphandbook.org/
RAMP Training Courses
http://www.nyphp.org/ramp