note 25953 deleted from function.mysql-query by didou
| From: | didou@php.net | Date: | Sat, 17 May 2003 18:55:15 +0000 |
| Subject: | note 25953 deleted from function.mysql-query by didou | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-48208@lists.php.net to get a copy of this message | ||
Note Submitter: phpinfo@t-online.de
Writing a function to send multiple queries (delimited by ';') as shown in a user message
above is really bad for security:
Let's assume you have a input form, with field login_number.
Instead of inserting the individual number 1374 an user inserts "1374;delete from login".
When you forget to check this input, and the table login exists, then good night!
Also it's not possible to determine which query failed in case of an error. I don't see
any need to combine some queries. It's not faster than sending single queries, its a security
hole.