note 32835 deleted from security.database by didou

From: Date: Mon, 04 Aug 2003 22:03:09 +0000
Subject: note 32835 deleted from security.database by didou
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-53350@lists.php.net to get a copy of this message
Note Submitter: Gustavo el Geranie ---- Even if you have a numerical field, you can compare it to a numerical value in quotes: xx integer(10) select * from test where xx=7 is the same as select * from test where xx='7' That means if you do an addslashes() for each user input and put the user input value in the query in quotes for all kind of fields, you should be on the safe side.

« previous php.notes (#53350) next »