note 113587 added to mysqli.error
| From: | asmith16 at littlesvr dot ca | Date: | Fri, 01 Nov 2013 23:42:57 +0000 |
| Subject: | note 113587 added to mysqli.error | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-197381@lists.php.net to get a copy of this message | ||
Please note that the string returned may contain data initially provided by the user, possibly
making your code vulnerable to XSS.
So even if you escape everything in your SQL query using mysqli_real_escape_string(), make sure that
if you plan to display the string returned by mysqli_error() you run that string through
htmlspecialchars().
As far as I can tell the two escape functions don't escape the same characters, which is why
you need both (the first for SQL and the second for HTML/JS).
----
Server IP: 64.71.164.2
Probable Submitter: 76.64.94.70
----
Manual Page -- http://php.net/manual/en/mysqli.error.php
Edit -- https://master.php.net/note/edit/113587
Del: integrated -- https://master.php.net/note/delete/113587/integrated
Del: useless -- https://master.php.net/note/delete/113587/useless
Del: bad code -- https://master.php.net/note/delete/113587/bad+code
Del: spam -- https://master.php.net/note/delete/113587/spam
Del: non-english -- https://master.php.net/note/delete/113587/non-english
Del: in docs -- https://master.php.net/note/delete/113587/in+docs
Del: other reasons-- https://master.php.net/note/delete/113587
Reject -- https://master.php.net/note/reject/113587
Search -- https://master.php.net/manage/user-notes.php