note 48870 deleted from security.database.sql-injection by didou
| From: | didou@php.net | Date: | Mon, 10 Jan 2005 09:08:56 +0000 |
| Subject: | note 48870 deleted from security.database.sql-injection by didou | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-83032@lists.php.net to get a copy of this message | ||
Note Submitter: kestas.j.k [REMOVE - THIS] ATgmail.com
----
Any variables you place inside an SQL query should be wrapped in ''. eg
<?php
// [...]
$query="UPDATE users SET pass='".checkout($_GET['newpass'])."'
WHERE id='".checkout($_GET['id'])."'";
// [...]
?>
Just so long as your checkout() function makes absolutely sure there are no '' in the
returned variable SQL injection isn't an issue.