note 69796 added to function.mysql-real-escape-string
| From: | php-general at lists dot php dot net | Date: | Thu, 21 Sep 2006 13:54:02 +0000 |
| Subject: | note 69796 added to function.mysql-real-escape-string | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-117378@lists.php.net to get a copy of this message | ||
Example 3. A "Best Practice" query ---> BUG (in the example, not in PHP!)
$query = sprintf("SELECT * FROM users WHERE user=%s AND password=%s",
quote_smart($_POST['username']),
quote_smart($_POST['password']));
If $_POST['password'] is ABCDE ... all works....
SELECT * FROM users WHERE user='user' AND password='ABCDE'
If $_POST['password'] is 00779 .. quote_smart (is stupid) and think the password is a
number!!
SELECT * FROM users WHERE user='user' AND password=00779
And quotes on 00779 ? :P
----
Server IP: 66.163.161.117
Probable Submitter: 72.29.65.4
----
Manual Page -- http://www.php.net/manual/en/function.mysql-real-escape-string.php
Edit -- https://master.php.net/note/edit/69796
Del: integrated -- https://master.php.net/note/delete/69796/integrated
Del: useless -- https://master.php.net/note/delete/69796/useless
Del: bad code -- https://master.php.net/note/delete/69796/bad+code
Del: spam -- https://master.php.net/note/delete/69796/spam
Del: non-english -- https://master.php.net/note/delete/69796/non-english
Del: in docs -- https://master.php.net/note/delete/69796/in+docs
Del: other reasons-- https://master.php.net/note/delete/69796
Reject -- https://master.php.net/note/reject/69796
Search -- https://master.php.net/manage/user-notes.php