note 32835 added to security.database
| From: | Gustavo at rack1 dot php dot net | Date: | Sun, 08 Jun 2003 16:36:10 +0000 |
| Subject: | note 32835 added to security.database | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-49990@lists.php.net to get a copy of this message | ||
Even if you have a numerical field, you can compare it to a numerical value in quotes:
xx integer(10)
select * from test where xx=7
is the same as
select * from test where xx='7'
That means if you do an addslashes() for each user input and put the user input value in the query
in quotes for all kind of fields, you should be on the safe side.
----
Manual Page -- http://www.php.net/manual/en/security.database.php
Edit Note -- http://master.php.net/manage/user-notes.php?action=edit+32835
Delete Note -- http://master.php.net/manage/user-notes.php?action=delete+32835&report=yes
Reject Note -- http://master.php.net/manage/user-notes.php?action=reject+32835&report=yes