Re: Re: Disabling PHP tags by php.ini and CLI options

From: Date: Wed, 11 Apr 2012 06:49:13 +0000
Subject: Re: Re: Disabling PHP tags by php.ini and CLI options
References: 1 2 3 4 5 6 7 8 9 10 11  Groups: php.internals 
Request: Send a blank email to internals+get-59720@lists.php.net to get a copy of this message
Oops, There are several language mistakes in previous mail, but this should be noted. Prepared query is not a perfect SQL injection countermeasure as it never escape nor parameterize identifiers/SQL literals. should be Prepared query is not a perfect SQL injection countermeasure as it never escape nor parameterize identifiers/SQL statements (e.g. ORDER BY ASC/DESC, etc). I've seen ASC/DESC as a parameter in a prepared query. It should be validated if they are user inputs. Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net 2012/4/11 Yasuo Ohgaki <yohgaki@ohgaki.net>: > Prepared query is not a perfect > SQL injection countermeasure as it never escape nor > parameterize identifiers/SQL literals.

« previous php.internals (#59720) next »