note 37565 modified in security.database by goba
| From: | goba@php.net | Date: | Mon, 02 Feb 2004 19:20:41 +0000 |
| Subject: | note 37565 modified in security.database by goba | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-64560@lists.php.net to get a copy of this message | ||
i use the following functions for all variables inside mysql queries:
<?php
function sqlstr($s)
{
return "'" . mysql_escape_string($s) . "'";
}
// example query:
mysql_query("SELECT * FROM users WHERE username=" . sqlstr($_REQUEST['name']) .
" AND password=" . sqlstr($_REQUEST['password']));
?>
note that you can use sqlstr() for integer fields, too.
mysql accepts SELECT * FROM table WHERE intfield='2'
--was--
i use the following functions for all variables inside mysql queries:
function sqlstr($s)
{
return "'" . mysql_escape_string($s) . "'";
}
example query:
mysql_query("SELECT * FROM users WHERE
username=".sqlstr($_REQUEST['name'])." AND
password=".sqlstr($_REQUEST['password']));
note that you can use sqlstr() for integer fields, too.
mysql accepts SELECT * FROM table WHERE intfield='2'
http://www.php.net/manual/en/security.database.php