note 56271 added to function.mysql-real-escape-string
| From: | jesper at snt dot utwente dot nl | Date: | Mon, 29 Aug 2005 12:43:39 +0000 |
| Subject: | note 56271 added to function.mysql-real-escape-string | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-94335@lists.php.net to get a copy of this message | ||
I use:
<?php
$username = ereg_replace("\\"|'| .*", "",
$_POST["username"]);
?>
This will remove all quotes and everything after the first whitespace. This will remove most
SQL-injection vulnerabilities for variables which shouldn't allow whitespaces or quotes. (like
usernames)
----
Manual Page -- http://www.php.net/manual/en/function.mysql-real-escape-string.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+56271
Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+56271&report=yes&reason=added+to+the+manual
Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+56271&report=yes&reason=bad+code
Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+56271&report=yes&reason=spam
Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+56271&report=yes&reason=useless
Delete: non-english -- http://master.php.net/manage/user-notes.php?action=delete+56271&report=yes&reason=non-english
Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+56271&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+56271&report=yes
Search -- http://master.php.net/manage/user-notes.php