note 50513 added to security.database.sql-injection

From: Date: Wed, 02 Mar 2005 13:10:48 +0000
Subject: note 50513 added to security.database.sql-injection
Groups: php.notes 
Request: Send a blank email to php-notes+get-85776@lists.php.net to get a copy of this message
I think, this small script can be usefull against sql-injections. <? function ekran($var) { if(is_array($var) != 1) { if($var != mysql_real_escape_string($var)) error_inform(); return mysql_real_escape_string($var); } else return array_filter($var); } function check_params() { array_filter($_GET, "ekran"); array_filter($_POST, "ekran"); array_filter($_COOKIE, "ekran"); } @import_request_variables("CGP", ""); ?> you can define "error_inform()" function to log(or send mail) abnormal values. ---- Manual Page -- http://www.php.net/manual/en/security.database.sql-injection.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+50513 Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+50513&report=yes&reason=added+to+the+manual Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+50513&report=yes&reason=bad+code Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+50513&report=yes&reason=spam Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+50513&report=yes&reason=useless Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+50513&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+50513&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#85776) next »