note 71990 deleted from function.mysql-real-escape-string by nlopess
| From: | nlopess@php.net | Date: | Sun, 31 Dec 2006 12:23:12 +0000 |
| Subject: | note 71990 deleted from function.mysql-real-escape-string by nlopess | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-121135@lists.php.net to get a copy of this message | ||
Note Submitter: http://whitemarker.blogspot.com
----
It is important to avoid SQL injection. One great way is to have a replacement for the sprintf
example shown above, and automatically run quote_smart on every parameter (except the first).
<?php
function qprintf()
{
//note the use of variable-length argument lists
$numargs = func_num_args();
$arg_list = func_num_args();
$format = $arg_list[0];
$arg_list2 = array();
for($i = 1; $i < $numargs; $i++)
$arg_list2[] = quote_smart($arg_list[$i]);
return vsprintf($format, $arg_list2);
}
// Make a safe query
$query = qprintf("SELECT * FROM users WHERE user=%s AND password=%s",
$_POST['username'],
$_POST['password']);
?>