note 48870 deleted from security.database.sql-injection by didou

From: Date: Mon, 10 Jan 2005 09:08:56 +0000
Subject: note 48870 deleted from security.database.sql-injection by didou
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-83032@lists.php.net to get a copy of this message
Note Submitter: kestas.j.k [REMOVE - THIS] ATgmail.com ---- Any variables you place inside an SQL query should be wrapped in ''. eg <?php // [...] $query="UPDATE users SET pass='".checkout($_GET['newpass'])."' WHERE id='".checkout($_GET['id'])."'"; // [...] ?> Just so long as your checkout() function makes absolutely sure there are no '' in the returned variable SQL injection isn't an issue.

« previous php.notes (#83032) next »