note 40789 deleted from function.mysql-escape-string by aidan

From: Date: Wed, 11 Aug 2004 14:06:09 +0000
Subject: note 40789 deleted from function.mysql-escape-string by aidan
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-74443@lists.php.net to get a copy of this message
Note Submitter: vladimir-dozen@mail.ru ---- <?php $query = "DELETE FROM user WHERE id=" . $id; mysql_query($query); ?> mysql_escape_string doesn't help here if we somehow get a param "5 OR 1=1" instead of simple 5. We'll end up with clear tab;e. I attempted to introduce a kind of type-safety into the SQL code via using of sprintf. The idea is in that the place of param binding is marked with %d or %s, so sprintf takes care of numerical params, and mysql_escape_string -- of strings: <?php> function query() { $aa = func_get_args(); foreach( $aa as $i => $val ) { if( $i == 0 ) continue; // format string if( is_string($val) ) { $val = mysql_escape_string($val); $aa[$i] = "'" . $val . "'"; } } $q = call_user_func_array('sprintf', $aa); $result = mysql_query($q) or die(mysql_error()); $ret = array(); while( $row = mysql_fetch_array($result) ) { $ret[] = $row; } return $ret; } ?> A call could look like: <?php $cat = SQL::query("delete from user where id=%d,$id); ?>

« previous php.notes (#74443) next »