Re: Re: PHP 4.3.3RC3 Released
| From: | Ard Biesheuvel | Date: | Fri, 15 Aug 2003 09:19:47 +0000 |
| Subject: | Re: Re: PHP 4.3.3RC3 Released | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-3987@lists.php.net to get a copy of this message | ||
> The problem is string compositing SQL queries. With a SQL command
> builder interface, query hacks don't occur. Right now, string
> compositing mysql queries with unvalidated input often results in just
> minor bugs, as from what I hear the mysql extention can't do chained
> queries yet, so there's no risk of someone injecting whatever SQL they
> choose, making it much harder to do evil.
Instead of
'SELECT .. WHERE id=$id'
write
'SELECT ... WHERE id='. (int)$id
Instead of
'SELECT .. WHERE name=$name'
write
'SELECT ... WHERE name=" '.addslashes($name).' " '
Problem solved forever
Ard