note 35132 added to function.mysql-escape-string

From: Date: Wed, 20 Aug 2003 20:51:03 +0000
Subject: note 35132 added to function.mysql-escape-string
Groups: php.notes 
Request: Send a blank email to php-notes+get-54777@lists.php.net to get a copy of this message
although "; DROP TABLE..." is not possible in some sql databases, the problem is still real! eg: $user=$_SESSION['USER']; $row=$_GET['ROW']; "DELETE FROM tbl WHERE USER='$user' AND ROW='$row' " simple attack: submit $row=" ' OR USER!='0" lazy sql handling implies unsafe data. ---- Manual Page -- http://www.php.net/manual/en/function.mysql-escape-string.php Edit Note -- http://master.php.net/manage/user-notes.php?action=edit+35132 Delete Note -- http://master.php.net/manage/user-notes.php?action=delete+35132&report=yes Reject Note -- http://master.php.net/manage/user-notes.php?action=reject+35132&report=yes

« previous php.notes (#54777) next »