note 32082 deleted from function.mysql-escape-string by didou

From: Date: Sat, 17 May 2003 20:03:45 +0000
Subject: note 32082 deleted from function.mysql-escape-string by didou
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-48234@lists.php.net to get a copy of this message
Note Submitter: Another solution to this: > <?php > $name = mysql_escape( $name ); > $query = "SELECT * FROM adresses WHERE name='$name' AND > private='N'"; > mysql_query($query); > ?> > > Without mysql_escape a user could set name to "' OR 1=1 OR ''='" > > effectively leading to the query: > SELECT * FROM adresses WHERE name='' OR 1=1 OR ''='' AND > private='N' > > which will give all adresses, including private ones. would be to enclose all your WHERE statements in parens e.g. $query = "SELECT * FROM adresses WHERE (name='$name') AND (private='N')";

« previous php.notes (#48234) next »