note 68223 added to tutorial.forms

From: Date: Tue, 18 Jul 2006 20:44:57 +0000
Subject: note 68223 added to tutorial.forms
Groups: php.notes 
Request: Send a blank email to php-notes+get-114900@lists.php.net to get a copy of this message
> It is easier to create a link called > /website/deleteuser.php?id=<userid> for each, where > deleteuser.php contains the (pseudocode): > $sql = "DELETE FROM usertable WHERE id = " . (int) $_GET['id']; Never pass raw data from the user directly into a string that will be passed on to be executed by something else (in this case SQL). In this case there is no check that the id coming back was ever on the table being displayed - you have given the web user the ability to delete anyone just by editing the name of the page requested. In this case the id is cast to an int at least. Without the cast it would be possible to inject ANY sql into the database by asking (for example) /website/deleteuser.php?id="0; select * from another_table;" ---- Server IP: 64.71.164.2 Probable Submitter: 198.62.250.120 ---- X-Spam-Status: No, hits=3.1 required=5.0 tests=DATE_MISSING,FROM_NO_LOWER autolearn=no version=2.64 ---- Manual Page -- http://www.php.net/manual/en/tutorial.forms.php Edit -- http://master.php.net/note/edit/68223 Del: integrated -- http://master.php.net/note/delete/68223/integrated Del: useless -- http://master.php.net/note/delete/68223/useless Del: bad code -- http://master.php.net/note/delete/68223/bad+code Del: spam -- http://master.php.net/note/delete/68223/spam Del: non-english -- http://master.php.net/note/delete/68223/non-english Del: in docs -- http://master.php.net/note/delete/68223/in+docs Del: other reasons-- http://master.php.net/note/delete/68223 Reject -- http://master.php.net/note/reject/68223 Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#114900) next »