note 40956 deleted from security.database by aidan
| From: | aidan@php.net | Date: | Tue, 07 Sep 2004 23:00:33 +0000 |
| Subject: | note 40956 deleted from security.database by aidan | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-76176@lists.php.net to get a copy of this message | ||
Note Submitter: rob at 2him dot us
----
the example regarding the sql statement injection for mysql does not make any sense as the
mysql_query function does not allow semicolons within the query, unless of course multiple queries
was part of the original script then security need be implemented. if not, then the script will fail
displaying an error at the point of the semicolon.
in addition, the query string in the same example contains a semicolon at the end, which is in
violation of the note to not include semicolons.