note 21598 added to function.mysql-query

From: Date: Mon, 20 May 2002 19:30:12 +0000
Subject: note 21598 added to function.mysql-query
Groups: php.notes 
Request: Send a blank email to php-notes+get-30811@lists.php.net to get a copy of this message
Here is a danger that I accidently came across. I hope knowledge of it it will save others from the grief it caused me! Consider the following SQL statement expressed as a PHP statement: $strSQL="DELETE FROM clients WHERE client_id=".client_id; What I mean to put of course was: $strSQL="DELETE FROM clients WHERE client_id=".$client_id; However the first statement is expanded by PHP to: "DELETE FROM clients WHERE client_id=client_id" AND RUNNING THIS SQL QUERY WILL DELETE THE _WHOLE_ OF YOUR TABLE CONTENT!!! It is the equivalent of: "DELETE FROM clients;" This can really spoil your day! Frank -- http://www.php.net/manual/en/function.mysql-query.php http://master.php.net/manage/user-notes.php?action=edit+21598 http://master.php.net/manage/user-notes.php?action=delete+21598 http://master.php.net/manage/user-notes.php?action=reject+21598

« previous php.notes (#30811) next »