RE: [PHP-DEV] Re: PHP 4.3.3RC3 Released
| From: | Rasmus Lerdorf | Date: | Fri, 15 Aug 2003 05:52:38 +0000 |
| Subject: | RE: [PHP-DEV] Re: PHP 4.3.3RC3 Released | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-3976@lists.php.net to get a copy of this message | ||
On Thu, 14 Aug 2003, Steven Brown wrote:
> I found an example of passing unvalidated input into a SQL query, I
> didn't say it would lead to an exploit. The point was, yes, even you
> guys make this mistake. It's not a "Well, you should have learned to
> write secure code" type of issue. Everyone makes this mistake
> occasionally.
Unvalidated in what sense? We don't validate for multiple queries because
we have no need to do so.
-Rasmus