Re: SQL syntax error in PHP script. dunno what's wrong
| From: | Richard Lynch | Date: | Fri, 03 Aug 2001 20:34:20 +0000 |
| Subject: | Re: SQL syntax error in PHP script. dunno what's wrong | ||
| References: | 1 2 3 4 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-61178@lists.php.net to get a copy of this message | ||
Or, suppose your site has something like this:
$query = "update user set password = password('$password') where userid =
$userid";
All they have to do is alter $userid to, say, 1, which is probably *YOU*,
the admin, that has full access, and whammo, they have admin access...
--
WARNING richard@zend.com address is an endangered species -- Use
ceo@l-i-e.com
Wanna help me out? Like Music? Buy a CD: http://l-i-e.com/artists.htm
Volunteer a little time: http://chatmusic.com/volunteer.htm
----- Original Message -----
From: Werner Stuerenburg <ws@art-quarter.com>
To: Richard Lynch <ceo@l-i-e.com>
Cc: <php-general@lists.php.net>
Sent: Friday, August 03, 2001 3:49 AM
Subject: Re: [PHP] SQL syntax error in PHP script. dunno what's wrong
> >> insert into test values (0,''; DELETE FROM test; ',1);
> >> ERROR 1064: You have an error in your SQL syntax near '' at line 1
>
> what about
>
> insert into test values (0,'\'; DELETE FROM test; ',1);
>
> the character ' is used to denote the beginning and the end of a
> field value. If you have this character within the value, you
> will have to escape it. It's as simple as that.
>
> --
> Herzlich
> Werner Stuerenburg
>
> _________________________________________________
> ISIS Verlag, Teut 3, D-32683 Barntrup-Alverdissen
> Tel 0(049) 5224-997 407 · Fax 0(049) 5224-997 409
> http://pferdezeitung.de
>