RE: [PEAR-DEV] Re: [binarycloud-dev] FW: lets talk "metapear" - politics aside:-)
| From: | Stig S. Bakken | Date: | Tue, 19 Mar 2002 22:23:12 +0000 |
| Subject: | RE: [PEAR-DEV] Re: [binarycloud-dev] FW: lets talk "metapear" - politics aside:-) | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-5051@lists.php.net to get a copy of this message | ||
On Tue, 2002-03-19 at 18:39, Lukas Smith wrote:
> > The other advantage is that you don't need to quote your strings
> yourself,
> > avoiding any security problems from tainted data (eg. $_GET and $_POST
> > strings).
>
> Aeh how so?
> I am aware of the problem of possible "tainted" data but where does the
> data get handled differently from a "normal" query?
It is handled differently because all the right quoting is done behind
the scenes (either because the DB driver quotes for you, or because it
uses some bind mechanism). In a normal query you need to do the quoting
yourself.
- Stig