note 68223 deleted from tutorial.forms by philip

From: Date: Thu, 14 Sep 2006 00:27:49 +0000
Subject: note 68223 deleted from tutorial.forms by philip
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-117139@lists.php.net to get a copy of this message
Note Submitter: verisimilidude at sourceforge dot com ---- > It is easier to create a link called > /website/deleteuser.php?id=<userid> for each, where > deleteuser.php contains the (pseudocode): > $sql = "DELETE FROM usertable WHERE id = " . (int) $_GET['id']; Never pass raw data from the user directly into a string that will be passed on to be executed by something else (in this case SQL). In this case there is no check that the id coming back was ever on the table being displayed - you have given the web user the ability to delete anyone just by editing the name of the page requested. In this case the id is cast to an int at least. Without the cast it would be possible to inject ANY sql into the database by asking (for example) /website/deleteuser.php?id="0; select * from another_table;"

« previous php.notes (#117139) next »