note 32082 added to function.mysql-escape-string
| From: | php-general at lists dot php dot net | Date: | Thu, 15 May 2003 21:32:10 +0000 |
| Subject: | note 32082 added to function.mysql-escape-string | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-48046@lists.php.net to get a copy of this message | ||
Another solution to this:
> <?php
> $name = mysql_escape( $name );
> $query = "SELECT * FROM adresses WHERE name='$name' AND
> private='N'";
> mysql_query($query);
> ?>
>
> Without mysql_escape a user could set name to "' OR 1=1 OR ''='"
>
> effectively leading to the query:
> SELECT * FROM adresses WHERE name='' OR 1=1 OR ''='' AND
> private='N'
>
> which will give all adresses, including private ones.
would be to enclose all your WHERE statements in parens e.g.
$query = "SELECT * FROM adresses WHERE (name='$name') AND
(private='N')";
--
http://www.php.net/manual/en/function.mysql-escape-string.php
http://master.php.net/manage/user-notes.php?action=edit+32082
http://master.php.net/manage/user-notes.php?action=delete+32082
http://master.php.net/manage/user-notes.php?action=reject+32082