note 15792 deleted from function.mysql-escape-string by jimw

From: Date: Wed, 03 Oct 2001 17:18:12 +0000
Subject: note 15792 deleted from function.mysql-escape-string by jimw
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-18516@lists.php.net to get a copy of this message
Addition to the notes above: It is actually very unlikely that a user could do such a think as MrUser"; DROP DATABASE mysql; First of all, the user would have to find out the exact form of your query in order to make a valid mySQL query. I don't know anyone who would only use this sort of a query: INSERT INTO TABLE (User) values ('MrUser'); Plus a webmaster with only a virtual host would never be given access to any other database then his own, and most certain not to the one called mysql.

« previous php.notes (#18516) next »