RE: [PHP] ODBC_EXECUTE has a DANGEROUS 'feature'!!!

From: Date: Mon, 11 Feb 2002 14:33:53 +0000
Subject: RE: [PHP] ODBC_EXECUTE has a DANGEROUS 'feature'!!!
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-84273@lists.php.net to get a copy of this message
> I understand you try to 'protect' your own product, but you have to > stay a bit realistic about some things. Ofcourse I check the input. > But you know... there's absolutely nothing wrong with allowing > quotes to be stored in the database. It's just that awful 'feature' > that makes it rather dangerous to do. If that feature/bug was > documented _anywhere_ it would still not be good, but at least > someone would know that PHP does this. But no... it's not > documented, not anywhere! You can't check user input on stuff you > don't know it can harm anything. Like I said... quotes are very > normal to be allowed in the database. > > It would be a good thing if you guys do something of: > > 1. Good rid of the bug(/feature) right a way or > 2. Document it clearly. Eg. in the documentation of odbc_execute(). > I'll echo Lars that you should always validate data, whether or not you assume it to be safe. That being said, if '/etc/passwd' is readable by your webserver you've got bigger problems. Best regards, Andrew Hill Director of Technology Evangelism http://www.openlinksw.com/virtuoso/whatis.htm OpenLink Virtuoso Internet Data Integration Server

« previous php.general (#84273) next »