note 25953 deleted from function.mysql-query by didou

From: Date: Sat, 17 May 2003 18:55:15 +0000
Subject: note 25953 deleted from function.mysql-query by didou
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-48208@lists.php.net to get a copy of this message
Note Submitter: phpinfo@t-online.de Writing a function to send multiple queries (delimited by ';') as shown in a user message above is really bad for security: Let's assume you have a input form, with field login_number. Instead of inserting the individual number 1374 an user inserts "1374;delete from login". When you forget to check this input, and the table login exists, then good night! Also it's not possible to determine which query failed in case of an error. I don't see any need to combine some queries. It's not faster than sending single queries, its a security hole.

« previous php.notes (#48208) next »