note 15792 added to function.mysql-escape-string
| From: | webmaster at datamike dot org | Date: | Wed, 03 Oct 2001 09:36:07 +0000 |
| Subject: | note 15792 added to function.mysql-escape-string | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-18502@lists.php.net to get a copy of this message | ||
Addition to the notes above:
It is actually very unlikely that a user could do such a think as
MrUser"; DROP DATABASE mysql;
First of all, the user would have to find out the exact form of your query in order to make a valid
mySQL query. I don't know anyone who would only use this sort of a query:
INSERT INTO TABLE (User) values ('MrUser');
Plus a webmaster with only a virtual host would never be given access to any other database then his
own, and most certain not to the one called mysql.
--
http://www.php.net/manual/en/function.mysql-escape-string.php
http://master.php.net/manage/user-notes.php?action=edit+15792
http://master.php.net/manage/user-notes.php?action=delete+15792
http://master.php.net/manage/user-notes.php?action=reject+15792