Re: SQL syntax error in PHP script. dunno what's wrong

From: Date: Fri, 03 Aug 2001 20:34:20 +0000
Subject: Re: SQL syntax error in PHP script. dunno what's wrong
References: 1 2 3 4  Groups: php.general 
Request: Send a blank email to php-general+get-61178@lists.php.net to get a copy of this message
Or, suppose your site has something like this: $query = "update user set password = password('$password') where userid = $userid"; All they have to do is alter $userid to, say, 1, which is probably *YOU*, the admin, that has full access, and whammo, they have admin access... -- WARNING richard@zend.com address is an endangered species -- Use ceo@l-i-e.com Wanna help me out? Like Music? Buy a CD: http://l-i-e.com/artists.htm Volunteer a little time: http://chatmusic.com/volunteer.htm ----- Original Message ----- From: Werner Stuerenburg <ws@art-quarter.com> To: Richard Lynch <ceo@l-i-e.com> Cc: <php-general@lists.php.net> Sent: Friday, August 03, 2001 3:49 AM Subject: Re: [PHP] SQL syntax error in PHP script. dunno what's wrong > >> insert into test values (0,''; DELETE FROM test; ',1); > >> ERROR 1064: You have an error in your SQL syntax near '' at line 1 > > what about > > insert into test values (0,'\'; DELETE FROM test; ',1); > > the character ' is used to denote the beginning and the end of a > field value. If you have this character within the value, you > will have to escape it. It's as simple as that. > > -- > Herzlich > Werner Stuerenburg > > _________________________________________________ > ISIS Verlag, Teut 3, D-32683 Barntrup-Alverdissen > Tel 0(049) 5224-997 407 · Fax 0(049) 5224-997 409 > http://pferdezeitung.de >

« previous php.general (#61178) next »