note 21321 deleted from security.database by didou

From: Date: Mon, 04 Aug 2003 22:04:02 +0000
Subject: note 21321 deleted from security.database by didou
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-53352@lists.php.net to get a copy of this message
Note Submitter: Jester@blackcodemail.com ---- Very informative, I cannot stress enough to validate all input you are passing to an SQL query. If you expect an int, use is_int(), if it's a fractional number, use is_float(), for example: if(!is_int($_POST['var'])) { die('Invalid input'); exit; } If it's a string do: if(!get_magic_quotes_gpc()) { $_POST['var'] = addslashes($_POST['var']); } To avoid people manipulating the query string, as shown above. If "magic quotes" is enabled the form input info will automatically have slashes added, you only need to do it if PHP isn't set up to use "magic quotes". Be very careful, I have made alot of mistakes with SQL queries in the past.

« previous php.notes (#53352) next »