note 21598 added to function.mysql-query
| From: | frank at boumphrey dot com | Date: | Mon, 20 May 2002 19:30:12 +0000 |
| Subject: | note 21598 added to function.mysql-query | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-30811@lists.php.net to get a copy of this message | ||
Here is a danger that I accidently came across. I hope knowledge of it it will save others from the
grief it caused me!
Consider the following SQL statement expressed as a PHP statement:
$strSQL="DELETE FROM clients WHERE client_id=".client_id;
What I mean to put of course was:
$strSQL="DELETE FROM clients WHERE client_id=".$client_id;
However the first statement is expanded by PHP to:
"DELETE FROM clients WHERE client_id=client_id"
AND RUNNING THIS SQL QUERY WILL DELETE THE _WHOLE_ OF YOUR TABLE CONTENT!!!
It is the equivalent of:
"DELETE FROM clients;"
This can really spoil your day!
Frank
--
http://www.php.net/manual/en/function.mysql-query.php
http://master.php.net/manage/user-notes.php?action=edit+21598
http://master.php.net/manage/user-notes.php?action=delete+21598
http://master.php.net/manage/user-notes.php?action=reject+21598