note 21321 deleted from security.database by didou
| From: | didou@php.net | Date: | Mon, 04 Aug 2003 22:04:02 +0000 |
| Subject: | note 21321 deleted from security.database by didou | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-53352@lists.php.net to get a copy of this message | ||
Note Submitter: Jester@blackcodemail.com
----
Very informative, I cannot stress enough to validate all input you are passing to an SQL query.
If you expect an int, use is_int(), if it's a fractional number, use is_float(), for example:
if(!is_int($_POST['var'])) {
die('Invalid input');
exit;
}
If it's a string do:
if(!get_magic_quotes_gpc()) {
$_POST['var'] = addslashes($_POST['var']);
}
To avoid people manipulating the query string, as shown above. If "magic quotes" is
enabled the form input info will automatically have slashes added, you only need to do it if PHP
isn't set up to use "magic quotes".
Be very careful, I have made alot of mistakes with SQL queries in the past.