note 114045 deleted from function.intval by cmb
| From: | cmb@php.net | Date: | Sun, 16 Feb 2020 13:50:51 +0000 |
| Subject: | note 114045 deleted from function.intval by cmb | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-214148@lists.php.net to get a copy of this message | ||
Note Submitter: jplevene at netscape dot net
----
I have found intval very useful for database security.
If you are passing a value via
- Data from user input
- Data that you have stored RAW on DB (witch is the best way) and you are using on a new sql
statment
- Data from unknown/other origin
and the data is supposed to be an integer, I always run it through intval before I put it into the
query (or you could use real_escape_string)
This prevents hackers from passing the variable as an SQL statement instead of a number in order to
attack your database.