note 69962 added to function.odbc-exec

From: Date: Thu, 28 Sep 2006 03:19:33 +0000
Subject: note 69962 added to function.odbc-exec
Groups: php.notes 
Request: Send a blank email to php-notes+get-117761@lists.php.net to get a copy of this message
It is easy to inject evil code into SQL statements. This wraps parameters in quotes so they are not executable. In your own stored procedures you can convert the string to numeric as needed. function sql_make_string($sin){ return "'".str_replace("'","''",$sin)."'"; } // this may delete all data from MYTABLE $evil = "734'; DELETE FROM MYTABLE; print 'ha ha"; $sql = "SELECT * FROM MYTABLE WHERE mykey = '$evil'"; $rst = odbc_exec($connection,$sql); // this probably will not delete the data. $good = sql_make_string($evil); $sql = "SELECT * FROM MYTABLE WHERE mykey =".$good $rst = odbc_exec($connection,$sql); ---- Server IP: 216.194.113.175 Probable Submitter: 148.85.184.125 ---- Manual Page -- http://www.php.net/manual/en/function.odbc-exec.php Edit -- https://master.php.net/note/edit/69962 Del: integrated -- https://master.php.net/note/delete/69962/integrated Del: useless -- https://master.php.net/note/delete/69962/useless Del: bad code -- https://master.php.net/note/delete/69962/bad+code Del: spam -- https://master.php.net/note/delete/69962/spam Del: non-english -- https://master.php.net/note/delete/69962/non-english Del: in docs -- https://master.php.net/note/delete/69962/in+docs Del: other reasons-- https://master.php.net/note/delete/69962 Reject -- https://master.php.net/note/reject/69962 Search -- https://master.php.net/manage/user-notes.php

« previous php.notes (#117761) next »