Re: Re: PHP 4.3.3RC3 Released

From: Date: Fri, 15 Aug 2003 09:19:47 +0000
Subject: Re: Re: PHP 4.3.3RC3 Released
References: 1 2  Groups: php.internals 
Request: Send a blank email to internals+get-3987@lists.php.net to get a copy of this message
> The problem is string compositing SQL queries. With a SQL command > builder interface, query hacks don't occur. Right now, string > compositing mysql queries with unvalidated input often results in just > minor bugs, as from what I hear the mysql extention can't do chained > queries yet, so there's no risk of someone injecting whatever SQL they > choose, making it much harder to do evil. Instead of 'SELECT .. WHERE id=$id' write 'SELECT ... WHERE id='. (int)$id Instead of 'SELECT .. WHERE name=$name' write 'SELECT ... WHERE name=" '.addslashes($name).' " ' Problem solved forever Ard

« previous php.internals (#3987) next »