RE: [PHP] is it safe to stripslashes() on all form variables? [ s ecurity hole !!! ]
| From: | Johnson, Kirk | Date: | Mon, 16 Apr 2001 22:21:35 +0000 |
| Subject: | RE: [PHP] is it safe to stripslashes() on all form variables? [ s ecurity hole !!! ] | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-48819@lists.php.net to get a copy of this message | ||
Yasuo, I didn't quite follow this. What are those special characters below
in your $name example?
TIA
Kirk
> -----Original Message-----
> If you strip slashes, it will make a security hole.
>
> For example,
>
> SELECT * FROM tablename WHERE name = '$name';
> what if $name is
> \'garbage\';DROP TABLE tablename;SELECT \'something
>
> After stripslashes($name)
> SELECT * FROM table WHERE name = 'garbage';DROP TABLE tablename;SELECT
> 'something';
>
> Regards,
> --
> Yasuo Ohgaki