note 40789 deleted from function.mysql-escape-string by aidan
| From: | aidan@php.net | Date: | Wed, 11 Aug 2004 14:06:09 +0000 |
| Subject: | note 40789 deleted from function.mysql-escape-string by aidan | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-74443@lists.php.net to get a copy of this message | ||
Note Submitter: vladimir-dozen@mail.ru
----
<?php
$query = "DELETE FROM user WHERE id=" . $id;
mysql_query($query);
?>
mysql_escape_string doesn't help here if we somehow get
a param "5 OR 1=1" instead of simple 5. We'll end up with clear tab;e.
I attempted to introduce a kind of type-safety into the SQL code via using of sprintf. The idea is
in that the place of param binding is marked with %d or %s, so sprintf takes care of numerical
params, and mysql_escape_string -- of strings:
<?php>
function query()
{
$aa = func_get_args();
foreach( $aa as $i => $val )
{
if( $i == 0 ) continue; // format string
if( is_string($val) )
{
$val = mysql_escape_string($val);
$aa[$i] = "'" . $val . "'";
}
}
$q = call_user_func_array('sprintf', $aa);
$result = mysql_query($q) or die(mysql_error());
$ret = array();
while( $row = mysql_fetch_array($result) )
{
$ret[] = $row;
}
return $ret;
}
?>
A call could look like:
<?php
$cat = SQL::query("delete from user where id=%d,$id);
?>