note 15828 added to function.mysql-escape-string
| From: | php at filecast dot org | Date: | Thu, 04 Oct 2001 11:11:18 +0000 |
| Subject: | note 15828 added to function.mysql-escape-string | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-18558@lists.php.net to get a copy of this message | ||
Actually, a hacker couldn't drop tables like that -- the PHP mysql_query only supports one
command per line. Of course, you should still escape everything coming from the outside world
because maliciously modifying the parameters of the intended command is still possible.
--
http://www.php.net/manual/en/function.mysql-escape-string.php
http://master.php.net/manage/user-notes.php?action=edit+15828
http://master.php.net/manage/user-notes.php?action=delete+15828
http://master.php.net/manage/user-notes.php?action=reject+15828