Re: Re: PHP 4.3.3RC3 Released
| From: | Hartmut Holzgraefe | Date: | Thu, 14 Aug 2003 07:58:58 +0000 |
| Subject: | Re: Re: PHP 4.3.3RC3 Released | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-3905@lists.php.net to get a copy of this message | ||
Steven Brown wrote:
this is also possible with oracle, oci8 and other database extensions, mysql ist the only one where i'm sure about that chaining is *not* supported so the actual security hole is user code that puts *unverified* input into SQL queries, so opening the door for SQL injection whether it makes sense to disable command chaining or at least make it configurable with default 'off' in PHP database extensions is a topic that may need further discussion (i know that Georg has similar plans for mysqli in PHP 5), but claiming that command chaining is a '*huge*' security hole per se is not justified IMHO, this is more about how much protection against "shoot yourself in the foot" incidents PHP should offer ... -- Hartmut Holzgraefe <hartmut@php.net>How is this a security hole?E.g., $id = "0; drop bar"; lamesql_query("select foo from bar where id = $id");