RE: [PHP-DEV] Re: PHP 4.3.3RC3 Released
| From: | Marc Boeren | Date: | Thu, 14 Aug 2003 08:08:07 +0000 |
| Subject: | RE: [PHP-DEV] Re: PHP 4.3.3RC3 Released | ||
| Groups: | php.internals | ||
| Request: | Send a blank email to internals+get-3907@lists.php.net to get a copy of this message | ||
> that's the point. if the cracker can change only the end of
> the query, it's not so usefull for him (he can maximum get other id)
How about a form of dos:
'...where id = '.$id
with $id = '23129 or 1'
this will select all entries in the table which could result in DoS...
So, ultimately this problem is the coders responsibility.
Cheerio, Marc.