note 32835 deleted from security.database by didou
| From: | didou@php.net | Date: | Mon, 04 Aug 2003 22:03:09 +0000 |
| Subject: | note 32835 deleted from security.database by didou | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-53350@lists.php.net to get a copy of this message | ||
Note Submitter: Gustavo el Geranie
----
Even if you have a numerical field, you can compare it to a numerical value in quotes:
xx integer(10)
select * from test where xx=7
is the same as
select * from test where xx='7'
That means if you do an addslashes() for each user input and put the user input value in the query
in quotes for all kind of fields, you should be on the safe side.