Re: Inserting variables (Saga Continues)
| From: | Steve Edberg | Date: | Tue, 09 Oct 2001 17:26:27 +0000 |
| Subject: | Re: Inserting variables (Saga Continues) | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-70521@lists.php.net to get a copy of this message | ||
At 11:39 AM -0500 10/9/01, RoyW wrote:
The key problem I have is that the number of "q1, q2" items is variable - as few as just q1 other times q1, q2, ... q100 - which is why I "build" an SQL statement from the form and then pass it to the script I am still sooooo baffled why it is that I can not pass (as a HIDDEN variable from a form): $sqlstatement = "INSERT INTO mytable ('$q1', '$q2', '2001-10-09')" NOTE: when viewed in HTML format after being interpretted: <input type="hidden" name="sqlstatement" value="INSERT INTO tdefb4 VALUES ('$q1', '$q2', '2001-10-09')"> and then go: $query = $sqlstatement; //or "$sqlstatement" $result = MYSQL_QUERY($query);Aha! PHP has NO WAY to tell whether the ...('$q1', '$q2', '2001-10-09')... in the $sqlstatement variable is an actual value or something that should be parsed further; the $query = $sqlstatement line doesn't change this a bit. You need to investigate the eval() function here; you would do something like eval("\$query = $sqlstatement;"); There are some fine points to deal with in escaping variable names using eval; see http://www.php.net/eval Note that passing a query this way is a VERY!!! BAD!!! IDEA!!! unless this page is password protected, or used in an intranet by only trusted people; even then, it's probably not a good idea. One could easily hack the form submission to say <input type="hidden" name="sqlstatement" value="drop table tdefb4"> or <input type="hidden" name="sqlstatement" value="delete from tdefb4"> and your data is gone. I'm 99.9999999999999% sure there's a better way to do this. If you realllly want to do this, you could pass some authentication value - eg, the md5() value of sqlstatement concatenated with some password/username data - and compare these values before the actual query is done; that way, you could be reasonably sure the page hadn't been hacked. -steve
"Kamil Nowicki" <hilarion@elfin.pl> wrote in message news:00c401c150d0$ff24b560$d101a8c0@elfin...-- +------------------------ Open source questions? ------------------------+ | Steve Edberg University of California, Davis | | sbedberg@ucdavis.edu Computer Consultant | | http://aesric.ucdavis.edu/ http://pgfsun.ucdavis.edu/ | +----------- http://pgfsun.ucdavis.edu/open-source-tools.html -----------+From a form, I pass the variables "$q1" and $q2"I also pass the following ATTEMPTS on an variable that is an SQLstatement:INSERT INTO mytable ('$q1', '$q2', '2001-10-09') or INSERT INTO mytable ("$q1", "$q2", "2001-10-09") I have tried executing the SQL statement like this: $query = $sqlstatement; $result = MYSQL_QUERY($query); as well as $query = "$sqlstatement"; $result = MYSQL_QUERY($query); No matter what I get the values literally "q1" and "q2" sent to the table and NOT their respective valuesCause when You pass something from a form thai it is a string (no matterifthere's $q1 entered into it and that You have $q1 declared) and it's not interpreted, so the querry contains '$q1', '$q2' strings, not the variables values. The solution for You was allready presented: do not pass the querry as You did, but like this: <INPUT TYPE="whatever" NAME="querry" VALUE="INSERT INTO mytable ('replacer_1', 'replacer_2', '2001-10-09')"> <INPUT TYPE="whatever" NAME="q1" VALUE="some_value_1"> <INPUT TYPE="whatever" NAME="q2" VALUE="some_value_2"> and handle it: $querry = ereg_replace( "replacer_1", $q1, $querry ); $querry = ereg_replace( "replacer_2", $q2, $querry ); $result = MYSQL_QUERY($query);Kamil 'Hilarion' Nowicki