RE: [PEAR-DEV] Re: [binarycloud-dev] FW: lets talk "metapear" - politics aside:-)

From: Date: Tue, 19 Mar 2002 22:23:12 +0000
Subject: RE: [PEAR-DEV] Re: [binarycloud-dev] FW: lets talk "metapear" - politics aside:-)
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-5051@lists.php.net to get a copy of this message
On Tue, 2002-03-19 at 18:39, Lukas Smith wrote: > > The other advantage is that you don't need to quote your strings > yourself, > > avoiding any security problems from tainted data (eg. $_GET and $_POST > > strings). > > Aeh how so? > I am aware of the problem of possible "tainted" data but where does the > data get handled differently from a "normal" query? It is handled differently because all the right quoting is done behind the scenes (either because the DB driver quotes for you, or because it uses some bind mechanism). In a normal query you need to do the quoting yourself. - Stig

« previous php.pear.dev (#5051) next »