note 25953 added to function.mysql-query

From: Date: Sat, 12 Oct 2002 19:08:11 +0000
Subject: note 25953 added to function.mysql-query
Groups: php.notes 
Request: Send a blank email to php-notes+get-37980@lists.php.net to get a copy of this message
Writing a function to send multiple queries (delimited by ';') as shown in a user message above is really bad for security: Let's assume you have a input form, with field login_number. Instead of inserting the individual number 1374 an user inserts "1374;delete from login". When you forget to check this input, and the table login exists, then good night! Also it's not possible to determine which query failed in case of an error. I don't see any need to combine some queries. It's not faster than sending single queries, its a security hole. -- http://www.php.net/manual/en/function.mysql-query.php http://master.php.net/manage/user-notes.php?action=edit+25953 http://master.php.net/manage/user-notes.php?action=delete+25953 http://master.php.net/manage/user-notes.php?action=reject+25953

« previous php.notes (#37980) next »