note 32082 added to function.mysql-escape-string

From: Date: Thu, 15 May 2003 21:32:10 +0000
Subject: note 32082 added to function.mysql-escape-string
Groups: php.notes 
Request: Send a blank email to php-notes+get-48046@lists.php.net to get a copy of this message
Another solution to this: > <?php > $name = mysql_escape( $name ); > $query = "SELECT * FROM adresses WHERE name='$name' AND > private='N'"; > mysql_query($query); > ?> > > Without mysql_escape a user could set name to "' OR 1=1 OR ''='" > > effectively leading to the query: > SELECT * FROM adresses WHERE name='' OR 1=1 OR ''='' AND > private='N' > > which will give all adresses, including private ones. would be to enclose all your WHERE statements in parens e.g. $query = "SELECT * FROM adresses WHERE (name='$name') AND (private='N')"; -- http://www.php.net/manual/en/function.mysql-escape-string.php http://master.php.net/manage/user-notes.php?action=edit+32082 http://master.php.net/manage/user-notes.php?action=delete+32082 http://master.php.net/manage/user-notes.php?action=reject+32082

« previous php.notes (#48046) next »