note 69962 added to function.odbc-exec
| From: | delowinggmaildotcom at osu1 dot php dot net | Date: | Thu, 28 Sep 2006 03:19:33 +0000 |
| Subject: | note 69962 added to function.odbc-exec | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-117761@lists.php.net to get a copy of this message | ||
It is easy to inject evil code into SQL statements. This wraps parameters in quotes so they are not
executable. In your own stored procedures you can convert the string to numeric as needed.
function sql_make_string($sin){
return
"'".str_replace("'","''",$sin)."'";
}
// this may delete all data from MYTABLE
$evil = "734'; DELETE FROM MYTABLE; print 'ha ha";
$sql = "SELECT * FROM MYTABLE WHERE mykey = '$evil'";
$rst = odbc_exec($connection,$sql);
// this probably will not delete the data.
$good = sql_make_string($evil);
$sql = "SELECT * FROM MYTABLE WHERE mykey =".$good
$rst = odbc_exec($connection,$sql);
----
Server IP: 216.194.113.175
Probable Submitter: 148.85.184.125
----
Manual Page -- http://www.php.net/manual/en/function.odbc-exec.php
Edit -- https://master.php.net/note/edit/69962
Del: integrated -- https://master.php.net/note/delete/69962/integrated
Del: useless -- https://master.php.net/note/delete/69962/useless
Del: bad code -- https://master.php.net/note/delete/69962/bad+code
Del: spam -- https://master.php.net/note/delete/69962/spam
Del: non-english -- https://master.php.net/note/delete/69962/non-english
Del: in docs -- https://master.php.net/note/delete/69962/in+docs
Del: other reasons-- https://master.php.net/note/delete/69962
Reject -- https://master.php.net/note/reject/69962
Search -- https://master.php.net/manage/user-notes.php