note 21598 deleted from function.mysql-query by cece

From: Date: Sun, 14 Nov 2004 13:24:21 +0000
Subject: note 21598 deleted from function.mysql-query by cece
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-80500@lists.php.net to get a copy of this message
Note Submitter: frank at boumphrey dot com ---- Here is a danger that I accidently came across. I hope knowledge of it it will save others from the grief it caused me! Consider the following SQL statement expressed as a PHP statement: $strSQL="DELETE FROM clients WHERE client_id=".client_id; What I mean to put of course was: $strSQL="DELETE FROM clients WHERE client_id=".$client_id; However the first statement is expanded by PHP to: "DELETE FROM clients WHERE client_id=client_id" AND RUNNING THIS SQL QUERY WILL DELETE THE _WHOLE_ OF YOUR TABLE CONTENT!!! It is the equivalent of: "DELETE FROM clients;" This can really spoil your day! Frank

« previous php.notes (#80500) next »