note 71990 added to function.mysql-real-escape-string
| From: | http://whitemarker dot blogspot dot com at osu1 dot php dot net | Date: | Thu, 28 Dec 2006 01:01:26 +0000 |
| Subject: | note 71990 added to function.mysql-real-escape-string | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-120970@lists.php.net to get a copy of this message | ||
It is important to avoid SQL injection. One great way is to have a replacement for the sprintf
example shown above, and automatically run quote_smart on every parameter (except the first).
<?php
function qprintf()
{
//note the use of variable-length argument lists
$numargs = func_num_args();
$arg_list = func_num_args();
$format = $arg_list[0];
$arg_list2 = array();
for($i = 1; $i < $numargs; $i++)
$arg_list2[] = quote_smart($arg_list[$i]);
return vsprintf($format, $arg_list2);
}
// Make a safe query
$query = qprintf("SELECT * FROM users WHERE user=%s AND password=%s",
$_POST['username'],
$_POST['password']);
?>
----
Server IP: 216.194.113.175
Probable Submitter: 71.112.150.215
----
Manual Page -- http://www.php.net/manual/en/function.mysql-real-escape-string.php
Edit -- https://master.php.net/note/edit/71990
Del: integrated -- https://master.php.net/note/delete/71990/integrated
Del: useless -- https://master.php.net/note/delete/71990/useless
Del: bad code -- https://master.php.net/note/delete/71990/bad+code
Del: spam -- https://master.php.net/note/delete/71990/spam
Del: non-english -- https://master.php.net/note/delete/71990/non-english
Del: in docs -- https://master.php.net/note/delete/71990/in+docs
Del: other reasons-- https://master.php.net/note/delete/71990
Reject -- https://master.php.net/note/reject/71990
Search -- https://master.php.net/manage/user-notes.php