note 68223 deleted from tutorial.forms by philip
| From: | philip@php.net | Date: | Thu, 14 Sep 2006 00:27:49 +0000 |
| Subject: | note 68223 deleted from tutorial.forms by philip | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-117139@lists.php.net to get a copy of this message | ||
Note Submitter: verisimilidude at sourceforge dot com
----
> It is easier to create a link called
> /website/deleteuser.php?id=<userid> for each, where
> deleteuser.php contains the (pseudocode):
> $sql = "DELETE FROM usertable WHERE id = " . (int) $_GET['id'];
Never pass raw data from the user directly into a string that will be passed on to be executed by
something else (in this case SQL). In this case there is no check that the id coming back was ever
on the table being displayed - you have given the web user the ability to delete anyone just by
editing the name of the page requested.
In this case the id is cast to an int at least. Without the cast it would be possible to inject ANY
sql into the database by asking (for example) /website/deleteuser.php?id="0; select * from
another_table;"