note 34127 modified in function.mysql-real-escape-string by vincent
| From: | vincent@php.net | Date: | Sat, 23 Aug 2003 18:59:08 +0000 |
| Subject: | note 34127 modified in function.mysql-real-escape-string by vincent | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-54973@lists.php.net to get a copy of this message | ||
[Editors Note:
It's better to use
$new_num = intval($_POST['new_num']);
-- vincent@php.net ]
It should also be noted that escaping the data is a useless precaution unless you encapsulate ALL
submitted fields in quotation marks, including suspected numeric data. MySQL does not force you to
wrap your numbers in quotes, but it MUST be done to keep users from injecting code.
$new_num = $_POST['new_num'];
// SECURITY RISK
mysql_query("UPDATE user_info SET icq_num=$new_num WHERE my_num=1");
// better
mysql_query("UPDATE user_info SET icq_num='$new_num' WHERE
my_num='1'");
It is actually better to use option 2 anyway because MySQL takes longer to process unquoted
arguments in some cases. A good example is when you do a search against a character field using a
non-quoted number, much like the first example above (no idea why though).
This is correct as of MySQL 4.0.13.
--was--
It should also be noted that escaping the data is a useless precaution unless you encapsulate ALL
submitted fields in quotation marks, including suspected numeric data. MySQL does not force you to
wrap your numbers in quotes, but it MUST be done to keep users from injecting code.
$new_num = $_POST['new_num'];
// SECURITY RISK
mysql_query("UPDATE user_info SET icq_num=$new_num WHERE my_num=1");
// better
mysql_query("UPDATE user_info SET icq_num='$new_num' WHERE
my_num='1'");
It is actually better to use option 2 anyway because MySQL takes longer to process unquoted
arguments in some cases. A good example is when you do a search against a character field using a
non-quoted number, much like the first example above (no idea why though).
This is correct as of MySQL 4.0.13.
http://www.php.net/manual/en/function.mysql-real-escape-string.php