note 15796 modified in function.mysql-escape-string by didou

From: Date: Sat, 17 May 2003 19:58:41 +0000
Subject: note 15796 modified in function.mysql-escape-string by didou
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-48230@lists.php.net to get a copy of this message
Usage: <?php $name = mysql_escape_string( $name ); $query = "SELECT * FROM adresses WHERE name='$name' AND private='N'"; mysql_query($query); ?> Without mysql_escape_string a user could set name to "' OR 1=1 OR ''='" effectively leading to the query: SELECT * FROM adresses WHERE name='' OR 1=1 OR ''='' AND private='N' which will give all adresses, including private ones. Don't say people won't find out, very ofter query errors are displayed to the user, and also this is such a common mistake that hackers will simply GUESS things like this. --was-- Usage: <?php $name = mysql_escape( $name ); $query = "SELECT * FROM adresses WHERE name='$name' AND private='N'"; mysql_query($query); ?> Without mysql_escape a user could set name to "' OR 1=1 OR ''='" effectively leading to the query: SELECT * FROM adresses WHERE name='' OR 1=1 OR ''='' AND private='N' which will give all adresses, including private ones. Don't say people won't find out, very ofter query errors are displayed to the user, and also this is such a common mistake that hackers will simply GUESS things like this. http://www.php.net/manual/en/function.mysql-escape-string.php

« previous php.notes (#48230) next »