note 69796 added to function.mysql-real-escape-string

From: Date: Thu, 21 Sep 2006 13:54:02 +0000
Subject: note 69796 added to function.mysql-real-escape-string
Groups: php.notes 
Request: Send a blank email to php-notes+get-117378@lists.php.net to get a copy of this message
Example 3. A "Best Practice" query ---> BUG (in the example, not in PHP!) $query = sprintf("SELECT * FROM users WHERE user=%s AND password=%s", quote_smart($_POST['username']), quote_smart($_POST['password'])); If $_POST['password'] is ABCDE ... all works.... SELECT * FROM users WHERE user='user' AND password='ABCDE' If $_POST['password'] is 00779 .. quote_smart (is stupid) and think the password is a number!! SELECT * FROM users WHERE user='user' AND password=00779 And quotes on 00779 ? :P ---- Server IP: 66.163.161.117 Probable Submitter: 72.29.65.4 ---- Manual Page -- http://www.php.net/manual/en/function.mysql-real-escape-string.php Edit -- https://master.php.net/note/edit/69796 Del: integrated -- https://master.php.net/note/delete/69796/integrated Del: useless -- https://master.php.net/note/delete/69796/useless Del: bad code -- https://master.php.net/note/delete/69796/bad+code Del: spam -- https://master.php.net/note/delete/69796/spam Del: non-english -- https://master.php.net/note/delete/69796/non-english Del: in docs -- https://master.php.net/note/delete/69796/in+docs Del: other reasons-- https://master.php.net/note/delete/69796 Reject -- https://master.php.net/note/reject/69796 Search -- https://master.php.net/manage/user-notes.php

« previous php.notes (#117378) next »