note 68221 deleted from function.mysql-real-escape-string by philip

From: Date: Fri, 04 Sep 2015 20:39:09 +0000
Subject: note 68221 deleted from function.mysql-real-escape-string by philip
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-203678@lists.php.net to get a copy of this message
Note Submitter: kael dot shipman at DONTSPAMIT! dot gmail dot com ---- It seems to me that you could avoid many hassels by loading valid database values into an array at the beginning of the script, then instead of using user input to query the database directly, use it to query the array you've created. For example: <?php //you still have to query safely, so always use cleanup functions like eric256's $categories = sql_query("select catName from categories where pageID = ?",$_GET['pageID']); while ($cts = @mysql_fetch_row($categories)) { //making $cts both the name and the value of the array variable makes it easier to check for in the future. //obviously, this naming system wouldn't work for a multidimensional array $cat_ar[$cts[0]] = $cts[0]; } ... //user selects sorting criteria //this would be from a query string like '?cats[]=cha&cats[]=fah&cats[]=lah&cats[]=badValue...', etc. $cats = $_GET['cats']; //verify that values exist in database before building sorting query foreach($cats as $c) { if ($cat_ar[$c]) { //instead of in_array(); maybe I'm just lazy... (see above note) $cats1[] = "'".mysql_real_escape_string($c)."'"; } } $cats = $cats1; //$cats now contains the filtered and escaped values of the query string $cat_query = '&& (category_name = \''.implode(' || category_name = \'',$cats).'\')'; //build a sql query insert //$cat_query is now "&& (category_name = 'cha' || category_name = 'fah' || category_name = 'lah')" - badValue has been removed //since all values have already been verified and escaped, you can simply use them in a query //however, since $pageID hasn't been cleaned for this query, you still have to use your cleaning function $items = sql_query("SELECT * FROM items i, categories c WHERE i.catID = c.catID && pageID = ? $cat_query", $pageID);

« previous php.notes (#203678) next »