note 68223 added to tutorial.forms
| From: | verisimilidude at sourceforge dot com | Date: | Tue, 18 Jul 2006 20:44:57 +0000 |
| Subject: | note 68223 added to tutorial.forms | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-114900@lists.php.net to get a copy of this message | ||
> It is easier to create a link called
> /website/deleteuser.php?id=<userid> for each, where
> deleteuser.php contains the (pseudocode):
> $sql = "DELETE FROM usertable WHERE id = " . (int) $_GET['id'];
Never pass raw data from the user directly into a string that will be passed on to be executed by
something else (in this case SQL). In this case there is no check that the id coming back was ever
on the table being displayed - you have given the web user the ability to delete anyone just by
editing the name of the page requested.
In this case the id is cast to an int at least. Without the cast it would be possible to inject ANY
sql into the database by asking (for example) /website/deleteuser.php?id="0; select * from
another_table;"
----
Server IP: 64.71.164.2
Probable Submitter: 198.62.250.120
----
X-Spam-Status: No, hits=3.1 required=5.0 tests=DATE_MISSING,FROM_NO_LOWER
autolearn=no version=2.64
----
Manual Page -- http://www.php.net/manual/en/tutorial.forms.php
Edit -- http://master.php.net/note/edit/68223
Del: integrated -- http://master.php.net/note/delete/68223/integrated
Del: useless -- http://master.php.net/note/delete/68223/useless
Del: bad code -- http://master.php.net/note/delete/68223/bad+code
Del: spam -- http://master.php.net/note/delete/68223/spam
Del: non-english -- http://master.php.net/note/delete/68223/non-english
Del: in docs -- http://master.php.net/note/delete/68223/in+docs
Del: other reasons-- http://master.php.net/note/delete/68223
Reject -- http://master.php.net/note/reject/68223
Search -- http://master.php.net/manage/user-notes.php