RE: [PHP-DEV] Re: PHP 4.3.3RC3 Released

From: Date: Thu, 14 Aug 2003 08:08:07 +0000
Subject: RE: [PHP-DEV] Re: PHP 4.3.3RC3 Released
Groups: php.internals 
Request: Send a blank email to internals+get-3907@lists.php.net to get a copy of this message
> that's the point. if the cracker can change only the end of > the query, it's not so usefull for him (he can maximum get other id) How about a form of dos: '...where id = '.$id with $id = '23129 or 1' this will select all entries in the table which could result in DoS... So, ultimately this problem is the coders responsibility. Cheerio, Marc.

« previous php.internals (#3907) next »