note 90181 rejected from pdo.prepare by thiago

From: Date: Thu, 09 Apr 2009 12:14:10 +0000
Subject: note 90181 rejected from pdo.prepare by thiago
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-153010@lists.php.net to get a copy of this message
Note Submitter: linusnorton at gmail dot com ---- I don't think that it's bad design to have table names coming from an unsafe source. For example, if you're designing a CMS and give users the power to make their own plugins quite frequently they will do something silly like take a table name from a request. In this instance it should be the database framework that escapes the table name and I think it would be good if there was a better way of doing it than $pdo->prepare("SELECT * FROM ".addslashes($schema)."")->execute(); something like $pdo->prepare("SELECT * FROM ".$pdo->escape($schema)."")->execute(); would be nice.

« previous php.notes (#153010) next »