note 42571 added to function.mysql-escape-string
| From: | arcticdoom at !Spam&Die!pixelsaredead dot com | Date: | Fri, 21 May 2004 19:09:43 +0000 |
| Subject: | note 42571 added to function.mysql-escape-string | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-69921@lists.php.net to get a copy of this message | ||
Or, for that matter, you could just explicitly cast things you know should be numeric. For example,
adding zero to a value will cast it as a number:
<?php
$input = "15 OR 1=1";
echo "Input Before Cleaning: $input\\n"; // shows "15 OR 1=1"
// Uh-oh! User 15 is being evil!
$input += 0;
echo "Input after cleaning: $input"; // shows "15"
// Not this time, user 15. Muahahahahah!!!
?>
----
Manual Page -- http://www.php.net/manual/en/function.mysql-escape-string.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+42571
Delete -- http://master.php.net/manage/user-notes.php?action=delete+42571&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+42571&report=yes
Search -- http://master.php.net/manage/user-notes.php