note 15796 added to function.mysql-escape-string

From: Date: Wed, 03 Oct 2001 10:33:54 +0000
Subject: note 15796 added to function.mysql-escape-string
Groups: php.notes 
Request: Send a blank email to php-notes+get-18507@lists.php.net to get a copy of this message
Usage: <?php $name = mysql_escape( $name ); $query = "SELECT * FROM adresses WHERE name='$name' AND private='N'"; mysql_query($query); ?> Without mysql_escape a user could set name to "' OR 1=1 OR ''='" effectively leading to the query: SELECT * FROM adresses WHERE name='' OR 1=1 OR ''='' AND private='N' which will give all adresses, including private ones. Don't say people won't find out, very ofter query errors are displayed to the user, and also this is such a common mistake that hackers will simply GUESS things like this. -- http://www.php.net/manual/en/function.mysql-escape-string.php http://master.php.net/manage/user-notes.php?action=edit+15796 http://master.php.net/manage/user-notes.php?action=delete+15796 http://master.php.net/manage/user-notes.php?action=reject+15796

« previous php.notes (#18507) next »