note 15828 added to function.mysql-escape-string

From: Date: Thu, 04 Oct 2001 11:11:18 +0000
Subject: note 15828 added to function.mysql-escape-string
Groups: php.notes 
Request: Send a blank email to php-notes+get-18558@lists.php.net to get a copy of this message
Actually, a hacker couldn't drop tables like that -- the PHP mysql_query only supports one command per line. Of course, you should still escape everything coming from the outside world because maliciously modifying the parameters of the intended command is still possible. -- http://www.php.net/manual/en/function.mysql-escape-string.php http://master.php.net/manage/user-notes.php?action=edit+15828 http://master.php.net/manage/user-notes.php?action=delete+15828 http://master.php.net/manage/user-notes.php?action=reject+15828

« previous php.notes (#18558) next »