Re: [RFC] Safe Casting Functions

From: Date: Thu, 20 Nov 2014 07:50:42 +0000
Subject: Re: [RFC] Safe Casting Functions
References: 1 2 3 4 5  Groups: php.internals 
Request: Send a blank email to internals+get-79022@lists.php.net to get a copy of this message
On 20/11/14 07:29, Yasuo Ohgaki wrote: > $id = $_GET['id']; > pg_qeury("SELECT * FROM some_table WHERE id = $id;"); Anybody using that method of passing parameters to a database needs much better education. This particular proposal just adds yet another 'how not to' rather than actually fixing the underlying security problems. Tidy up what exists - don't create yet another set of functions that can still be abused. -- Lester Caine - G8HFL ----------------------------- Contact - http://lsces.co.uk/wiki/?page=contact L.S.Caine Electronic Services - http://lsces.co.uk EnquirySolve - http://enquirysolve.com/ Model Engineers Digital Workshop - http://medw.co.uk Rainbow Digital Media - http://rainbowdigitalmedia.co.uk

« previous php.internals (#79022) next »