note 71990 added to function.mysql-real-escape-string

From: Date: Thu, 28 Dec 2006 01:01:26 +0000
Subject: note 71990 added to function.mysql-real-escape-string
Groups: php.notes 
Request: Send a blank email to php-notes+get-120970@lists.php.net to get a copy of this message
It is important to avoid SQL injection. One great way is to have a replacement for the sprintf example shown above, and automatically run quote_smart on every parameter (except the first). <?php function qprintf() { //note the use of variable-length argument lists $numargs = func_num_args(); $arg_list = func_num_args(); $format = $arg_list[0]; $arg_list2 = array(); for($i = 1; $i < $numargs; $i++) $arg_list2[] = quote_smart($arg_list[$i]); return vsprintf($format, $arg_list2); } // Make a safe query $query = qprintf("SELECT * FROM users WHERE user=%s AND password=%s", $_POST['username'], $_POST['password']); ?> ---- Server IP: 216.194.113.175 Probable Submitter: 71.112.150.215 ---- Manual Page -- http://www.php.net/manual/en/function.mysql-real-escape-string.php Edit -- https://master.php.net/note/edit/71990 Del: integrated -- https://master.php.net/note/delete/71990/integrated Del: useless -- https://master.php.net/note/delete/71990/useless Del: bad code -- https://master.php.net/note/delete/71990/bad+code Del: spam -- https://master.php.net/note/delete/71990/spam Del: non-english -- https://master.php.net/note/delete/71990/non-english Del: in docs -- https://master.php.net/note/delete/71990/in+docs Del: other reasons-- https://master.php.net/note/delete/71990 Reject -- https://master.php.net/note/reject/71990 Search -- https://master.php.net/manage/user-notes.php

« previous php.notes (#120970) next »