note 68221 deleted from function.mysql-real-escape-string by philip
| From: | philip@php.net | Date: | Fri, 04 Sep 2015 20:39:09 +0000 |
| Subject: | note 68221 deleted from function.mysql-real-escape-string by philip | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-203678@lists.php.net to get a copy of this message | ||
Note Submitter: kael dot shipman at DONTSPAMIT! dot gmail dot com
----
It seems to me that you could avoid many hassels by loading valid database values into an array at
the beginning of the script, then instead of using user input to query the database directly, use it
to query the array you've created. For example:
<?php
//you still have to query safely, so always use cleanup functions like eric256's
$categories = sql_query("select catName from categories where pageID =
?",$_GET['pageID']);
while ($cts = @mysql_fetch_row($categories)) {
//making $cts both the name and the value of the array variable makes it easier to check for in the
future.
//obviously, this naming system wouldn't work for a multidimensional array
$cat_ar[$cts[0]] = $cts[0];
}
...
//user selects sorting criteria
//this would be from a query string like
'?cats[]=cha&cats[]=fah&cats[]=lah&cats[]=badValue...', etc.
$cats = $_GET['cats'];
//verify that values exist in database before building sorting query
foreach($cats as $c) {
if ($cat_ar[$c]) { //instead of in_array(); maybe I'm just lazy... (see above note)
$cats1[] = "'".mysql_real_escape_string($c)."'";
}
}
$cats = $cats1;
//$cats now contains the filtered and escaped values of the query string
$cat_query = '&& (category_name = \''.implode(' || category_name =
\'',$cats).'\')';
//build a sql query insert
//$cat_query is now "&& (category_name = 'cha' || category_name =
'fah' || category_name = 'lah')" - badValue has been removed
//since all values have already been verified and escaped, you can simply use them in a query
//however, since $pageID hasn't been cleaned for this query, you still have to use your
cleaning function
$items = sql_query("SELECT * FROM items i, categories c WHERE i.catID = c.catID &&
pageID = ? $cat_query", $pageID);