Re: PHP 4.3.3RC3 Released
| From: | Ard Biesheuvel | Date: | Thu, 14 Aug 2003 09:31:14 +0000 |
| Subject: | Re: PHP 4.3.3RC3 Released | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-3922@lists.php.net to get a copy of this message | ||
> What about hacking somehow the sqlite library to disallow chained
queries
> (or at least do it optionally)?
If you are unable or unwilling to verify the safety of your input,
use a database that supports params + binding (like Firebird :-))
Any input obtained from the client should be considered unsafe
(== tainted in Perl) and should be checked for correctness first.
In the described case, casting the value to a number if it's
expected to be numerical or putting quotes around it if it's expected
to be a string value will solve your problem. Disallowing chained
queries will prevent *every* developer from ever using it.
Ard