RE: [PHP] is it safe to stripslashes() on all form variables? [ s ecurity hole !!! ]

From: Date: Mon, 16 Apr 2001 22:21:35 +0000
Subject: RE: [PHP] is it safe to stripslashes() on all form variables? [ s ecurity hole !!! ]
Groups: php.general 
Request: Send a blank email to php-general+get-48819@lists.php.net to get a copy of this message
Yasuo, I didn't quite follow this. What are those special characters below in your $name example? TIA Kirk > -----Original Message----- > If you strip slashes, it will make a security hole. > > For example, > > SELECT * FROM tablename WHERE name = '$name'; > what if $name is > \'garbage\';DROP TABLE tablename;SELECT \'something > > After stripslashes($name) > SELECT * FROM table WHERE name = 'garbage';DROP TABLE tablename;SELECT > 'something'; > > Regards, > -- > Yasuo Ohgaki

« previous php.general (#48819) next »