note 35132 added to function.mysql-escape-string
| From: | bluefish at rack1 dot php dot net | Date: | Wed, 20 Aug 2003 20:51:03 +0000 |
| Subject: | note 35132 added to function.mysql-escape-string | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-54777@lists.php.net to get a copy of this message | ||
although "; DROP TABLE..." is not possible in some sql databases, the problem is still
real! eg:
$user=$_SESSION['USER'];
$row=$_GET['ROW'];
"DELETE FROM tbl WHERE USER='$user' AND ROW='$row' "
simple attack: submit $row=" ' OR USER!='0"
lazy sql handling implies unsafe data.
----
Manual Page -- http://www.php.net/manual/en/function.mysql-escape-string.php
Edit Note -- http://master.php.net/manage/user-notes.php?action=edit+35132
Delete Note -- http://master.php.net/manage/user-notes.php?action=delete+35132&report=yes
Reject Note -- http://master.php.net/manage/user-notes.php?action=reject+35132&report=yes