Re: is it safe to stripslashes() on all form variables?

From: Date: Tue, 17 Apr 2001 00:05:43 +0000
Subject: Re: is it safe to stripslashes() on all form variables?
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-48852@lists.php.net to get a copy of this message
Jesus that's pretty scary! So how should i go about doing this? ""Yasuo Ohgaki"" <yohgaki@hotmail.com> wrote in message news:9bflce$9p5$1@toye.p.sourceforge.net... > If you strip slashes, it will make a security hole. > > For example, > > SELECT * FROM tablename WHERE name = '$name'; > what if $name is > \'garbage\';DROP TABLE tablename;SELECT \'something > > After stripslashes($name) > SELECT * FROM table WHERE name = 'garbage';DROP TABLE tablename;SELECT > 'something'; > > Regards, > -- > Yasuo Ohgaki > > > ""Noah Spitzer-Williams"" <noahsw@cyberdude.com> wrote in message > news:9bf7ec$m1m$1@toye.p.sourceforge.net... > > would there be any problems caused if i used the stripslashes() function on > > all posted variables from a form to eliminate sql query errors? > > > > - Noah > > > > > > > > -- > > PHP General Mailing List (http://www.php.net/) > > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > > For additional commands, e-mail: php-general-help@lists.php.net > > To contact the list administrators, e-mail: php-list-admin@lists.php.net > > > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net >

« previous php.general (#48852) next »