note 69796 deleted from function.mysql-real-escape-string by bobby

From: Date: Thu, 21 Sep 2006 14:52:49 +0000
Subject: note 69796 deleted from function.mysql-real-escape-string by bobby
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-117379@lists.php.net to get a copy of this message
Note Submitter: ---- Example 3. A "Best Practice" query ---> BUG (in the example, not in PHP!) $query = sprintf("SELECT * FROM users WHERE user=%s AND password=%s", quote_smart($_POST['username']), quote_smart($_POST['password'])); If $_POST['password'] is ABCDE ... all works.... SELECT * FROM users WHERE user='user' AND password='ABCDE' If $_POST['password'] is 00779 .. quote_smart (is stupid) and think the password is a number!! SELECT * FROM users WHERE user='user' AND password=00779 And quotes on 00779 ? :P

« previous php.notes (#117379) next »