note 37565 modified in security.database by goba

From: Date: Mon, 02 Feb 2004 19:20:41 +0000
Subject: note 37565 modified in security.database by goba
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-64560@lists.php.net to get a copy of this message
i use the following functions for all variables inside mysql queries: <?php function sqlstr($s) { return "'" . mysql_escape_string($s) . "'"; } // example query: mysql_query("SELECT * FROM users WHERE username=" . sqlstr($_REQUEST['name']) . " AND password=" . sqlstr($_REQUEST['password'])); ?> note that you can use sqlstr() for integer fields, too. mysql accepts SELECT * FROM table WHERE intfield='2' --was-- i use the following functions for all variables inside mysql queries: function sqlstr($s) { return "'" . mysql_escape_string($s) . "'"; } example query: mysql_query("SELECT * FROM users WHERE username=".sqlstr($_REQUEST['name'])." AND password=".sqlstr($_REQUEST['password'])); note that you can use sqlstr() for integer fields, too. mysql accepts SELECT * FROM table WHERE intfield='2' http://www.php.net/manual/en/security.database.php

« previous php.notes (#64560) next »