note 90181 rejected from pdo.prepare by thiago
| From: | thiago@php.net | Date: | Thu, 09 Apr 2009 12:14:10 +0000 |
| Subject: | note 90181 rejected from pdo.prepare by thiago | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-153010@lists.php.net to get a copy of this message | ||
Note Submitter: linusnorton at gmail dot com
----
I don't think that it's bad design to have table names coming from an unsafe source.
For example, if you're designing a CMS and give users the power to make their own plugins quite
frequently they will do something silly like take a table name from a request.
In this instance it should be the database framework that escapes the table name and I think it
would be good if there was a better way of doing it than
$pdo->prepare("SELECT * FROM
".addslashes($schema)."")->execute();
something like
$pdo->prepare("SELECT * FROM
".$pdo->escape($schema)."")->execute();
would be nice.