RE: [PHP-DEV] Re: PHP 4.3.3RC3 Released
| From: | Steven Brown | Date: | Thu, 14 Aug 2003 07:45:03 +0000 |
| Subject: | RE: [PHP-DEV] Re: PHP 4.3.3RC3 Released | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-3902@lists.php.net to get a copy of this message | ||
> -----Original Message-----
> From: Derick Rethans [mailto:derick@php.net]
> Sent: Thursday, August 14, 2003 12:33 AM
> To: moshe doron
> Cc: internals@lists.php.net
> Subject: Re: [PHP-DEV] Re: PHP 4.3.3RC3 Released
>
>
> On Thu, 14 Aug 2003, moshe doron wrote:
>
> > What about hacking somehow the sqlite library to disallow chained
> > queries (or at least do it optionally)?
> >
> > This behavior is *huge* security hole, allow to the cracker drop ur
> > database using simple select where query.
>
> How is this a security hole?
E.g.,
$id = "0; drop bar";
lamesql_query("select foo from bar where id = $id");