note 31989 added to security.database
| From: | costa at NOSPAM dot ca | Date: | Mon, 12 May 2003 06:39:28 +0000 |
| Subject: | note 31989 added to security.database | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-47866@lists.php.net to get a copy of this message | ||
We're told that ';' and '--' are potentially dangerous strings because of
their special significance to MySQL. But we're not told how to defend against them.
We can't really search and replace those strings because they may be valid (e.g. in msg board
post). Addslashes() doesn't touch them.
So I'm still scratching my head -- should be worry about those strings? If so, how?
--
http://www.php.net/manual/en/security.database.php
http://master.php.net/manage/user-notes.php?action=edit+31989
http://master.php.net/manage/user-notes.php?action=delete+31989
http://master.php.net/manage/user-notes.php?action=reject+31989