note 69796 deleted from function.mysql-real-escape-string by bobby
| From: | bobby@php.net | Date: | Thu, 21 Sep 2006 14:52:49 +0000 |
| Subject: | note 69796 deleted from function.mysql-real-escape-string by bobby | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-117379@lists.php.net to get a copy of this message | ||
Note Submitter:
----
Example 3. A "Best Practice" query ---> BUG (in the example, not in PHP!)
$query = sprintf("SELECT * FROM users WHERE user=%s AND password=%s",
quote_smart($_POST['username']),
quote_smart($_POST['password']));
If $_POST['password'] is ABCDE ... all works....
SELECT * FROM users WHERE user='user' AND password='ABCDE'
If $_POST['password'] is 00779 .. quote_smart (is stupid) and think the password is a
number!!
SELECT * FROM users WHERE user='user' AND password=00779
And quotes on 00779 ? :P