Re: is it safe to stripslashes() on all form variables?
| From: | Yasuo Ohgaki | Date: | Tue, 17 Apr 2001 02:15:56 +0000 |
| Subject: | Re: is it safe to stripslashes() on all form variables? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-48865@lists.php.net to get a copy of this message | ||
If you strip slashes, it will make a security hole.
For example,
SELECT * FROM tablename WHERE name = '$name';
what if $name is
\'garbage\';DROP TABLE tablename;SELECT \'something
After stripslashes($name)
SELECT * FROM table WHERE name = 'garbage';DROP TABLE tablename;SELECT
'something';
Regards,
--
Yasuo Ohgaki
""Noah Spitzer-Williams"" <noahsw@cyberdude.com> wrote in message
news:9bf7ec$m1m$1@toye.p.sourceforge.net...
> would there be any problems caused if i used the stripslashes() function on
> all posted variables from a form to eliminate sql query errors?
>
> - Noah
>
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>