note 15796 modified in function.mysql-escape-string by didou
| From: | didou@php.net | Date: | Sat, 17 May 2003 19:58:41 +0000 |
| Subject: | note 15796 modified in function.mysql-escape-string by didou | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-48230@lists.php.net to get a copy of this message | ||
Usage:
<?php
$name = mysql_escape_string( $name );
$query = "SELECT * FROM adresses WHERE name='$name' AND private='N'";
mysql_query($query);
?>
Without mysql_escape_string a user could set name to "' OR 1=1 OR
''='"
effectively leading to the query:
SELECT * FROM adresses WHERE name='' OR 1=1 OR ''='' AND
private='N'
which will give all adresses, including private ones.
Don't say people won't find out, very ofter query errors are displayed to the user, and
also this is such a common mistake that hackers will simply GUESS things like this.
--was--
Usage:
<?php
$name = mysql_escape( $name );
$query = "SELECT * FROM adresses WHERE name='$name' AND private='N'";
mysql_query($query);
?>
Without mysql_escape a user could set name to "' OR 1=1 OR ''='"
effectively leading to the query:
SELECT * FROM adresses WHERE name='' OR 1=1 OR ''='' AND
private='N'
which will give all adresses, including private ones.
Don't say people won't find out, very ofter query errors are displayed to the user, and
also this is such a common mistake that hackers will simply GUESS things like this.
http://www.php.net/manual/en/function.mysql-escape-string.php