note 25953 added to function.mysql-query
| From: | phpinfo at t-online dot de | Date: | Sat, 12 Oct 2002 19:08:11 +0000 |
| Subject: | note 25953 added to function.mysql-query | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-37980@lists.php.net to get a copy of this message | ||
Writing a function to send multiple queries (delimited by ';') as shown in a user message
above is really bad for security:
Let's assume you have a input form, with field login_number.
Instead of inserting the individual number 1374 an user inserts "1374;delete from login".
When you forget to check this input, and the table login exists, then good night!
Also it's not possible to determine which query failed in case of an error. I don't see
any need to combine some queries. It's not faster than sending single queries, its a security
hole.
--
http://www.php.net/manual/en/function.mysql-query.php
http://master.php.net/manage/user-notes.php?action=edit+25953
http://master.php.net/manage/user-notes.php?action=delete+25953
http://master.php.net/manage/user-notes.php?action=reject+25953