note 37565 added to security.database
| From: | php-general at lists dot php dot net | Date: | Wed, 19 Nov 2003 20:41:15 +0000 |
| Subject: | note 37565 added to security.database | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-60640@lists.php.net to get a copy of this message | ||
i use the following functions for all variables inside mysql queries:
function sqlstr($s)
{
return "'" . mysql_escape_string($s) . "'";
}
example query:
mysql_query("SELECT * FROM users WHERE
username=".sqlstr($_REQUEST['name'])." AND
password=".sqlstr($_REQUEST['password']));
note that you can use sqlstr() for integer fields, too.
mysql accepts SELECT * FROM table WHERE intfield='2'
----
Manual Page -- http://www.php.net/manual/en/security.database.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+37565
Delete -- http://master.php.net/manage/user-notes.php?action=delete+37565&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+37565&report=yes
Search -- http://master.php.net/manage/user-notes.php