Re: $ of variables, php, mysql

From: Date: Tue, 25 Nov 2003 21:12:33 +0000
Subject: Re: $ of variables, php, mysql
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-170939@lists.php.net to get a copy of this message
Hey thanks guys. Problem solved. --- Eugene Lee <list-php-1@fsck.net> wrote: > On Tue, Nov 25, 2003 at 11:38:27AM +0100, Marek > Kilimajer wrote: > : Eugene Lee wrote: > : > > : >Try using more variables to make life a little > easier to parse: > : > > : > $colname = $_FORM['form'] > : > $query = "select {$colname} from structure"; > : > $result = mysql_query($query); > : > while (($row = mysql_fetch_array($result)) !== > false) > : > { > : > echo $row[$colname]; > : > } > : > > : > : Very dangerous. $colname can be anything, e.g. > "mysql.user.password > : colname FROM mysql.user #" > > I wrote it out this way because: the other user > provided no source code, > I wanted to show working code, it was late and I > didn't feel like adding > anything to secure against intrusions like SQL > injection attacks. For > the sake of completeness, redo the first line above > as: > > $colname = mysql_escape_string($_FORM['form']); > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, visit: http://www.php.net/unsub.php > __________________________________ Do you Yahoo!? Free Pop-Up Blocker - Get it now http://companion.yahoo.com/

« previous php.general (#170939) next »