note 35132 deleted from function.mysql-escape-string by didou

From: Date: Thu, 21 Aug 2003 09:51:02 +0000
Subject: note 35132 deleted from function.mysql-escape-string by didou
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-54806@lists.php.net to get a copy of this message
Note Submitter: bluefish ---- although "; DROP TABLE..." is not possible in some sql databases, the problem is still real! eg: $user=$_SESSION['USER']; $row=$_GET['ROW']; "DELETE FROM tbl WHERE USER='$user' AND ROW='$row' " simple attack: submit $row=" ' OR USER!='0" lazy sql handling implies unsafe data.

« previous php.notes (#54806) next »