note 34127 modified in function.mysql-real-escape-string by vincent

From: Date: Sat, 23 Aug 2003 18:59:08 +0000
Subject: note 34127 modified in function.mysql-real-escape-string by vincent
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-54973@lists.php.net to get a copy of this message
[Editors Note: It's better to use $new_num = intval($_POST['new_num']); -- vincent@php.net ] It should also be noted that escaping the data is a useless precaution unless you encapsulate ALL submitted fields in quotation marks, including suspected numeric data. MySQL does not force you to wrap your numbers in quotes, but it MUST be done to keep users from injecting code. $new_num = $_POST['new_num']; // SECURITY RISK mysql_query("UPDATE user_info SET icq_num=$new_num WHERE my_num=1"); // better mysql_query("UPDATE user_info SET icq_num='$new_num' WHERE my_num='1'"); It is actually better to use option 2 anyway because MySQL takes longer to process unquoted arguments in some cases. A good example is when you do a search against a character field using a non-quoted number, much like the first example above (no idea why though). This is correct as of MySQL 4.0.13. --was-- It should also be noted that escaping the data is a useless precaution unless you encapsulate ALL submitted fields in quotation marks, including suspected numeric data. MySQL does not force you to wrap your numbers in quotes, but it MUST be done to keep users from injecting code. $new_num = $_POST['new_num']; // SECURITY RISK mysql_query("UPDATE user_info SET icq_num=$new_num WHERE my_num=1"); // better mysql_query("UPDATE user_info SET icq_num='$new_num' WHERE my_num='1'"); It is actually better to use option 2 anyway because MySQL takes longer to process unquoted arguments in some cases. A good example is when you do a search against a character field using a non-quoted number, much like the first example above (no idea why though). This is correct as of MySQL 4.0.13. http://www.php.net/manual/en/function.mysql-real-escape-string.php

« previous php.notes (#54973) next »