Re: security benefits of predefined variables
| From: | Rasmus Lerdorf | Date: | Wed, 16 Jan 2002 21:44:29 +0000 |
| Subject: | Re: security benefits of predefined variables | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-80841@lists.php.net to get a copy of this message | ||
> You can see where I'm going with this.
> Experiments of mine with using array elements within SQL statements
> brought some of my questioning to the list just last week. I found that
> the following did not work:
>
> $sql = "SELECT table.column FROM table WHERE criteria LIKE
> $myrow['variable']";
Inside a quoted string you don't use the single-quotes around the index.
So this would work:
$sql = "SELECT table.column FROM table WHERE criteria LIKE $myrow[variable]";
My preferred method is to use:
$sql = "SELECT table.column FROM table WHERE criteria LIKE " .
$myrow['variable'];
-Rasmus