Re: does "quote" DB filter out all dubious characters preventing sql injection?

From: Date: Thu, 07 Oct 2004 21:50:08 +0000
Subject: Re: does "quote" DB filter out all dubious characters preventing sql injection?
References: 1  Groups: php.pear.general 
Request: Send a blank email to pear-general+get-14805@lists.php.net to get a copy of this message
On Thu, 7 Oct 2004 14:43:08 -0700 (PDT), Stowe Spivey <spiveyspivey@yahoo.com> wrote: > I'd like to switch to using Pear but need to know how far I need to > go in securing the use input using DB pkg. > Well, the correct function now is quoteSmart(). It completely quotes the value, making sure that it goes into the DB as given. It stops SQL injection. For example: $val = 'blah";DELETE FROM table'; $db = DB::connect($dsn); $sth = $db->query('SELECT * FROM table WHERE column='.$db->quoteSmart($val)); This will search for "column" equal to exactly the string in $val. Also, there is a quoteIdentifier function which should be used for quoting table and column names. You only need to use this if you're using a reserved word for a table or column name, but it's useful otherwise too. $table = 'select'; $column = 'from'; $sth = $db->query('SELECT * FROM '.$db->quoteIdentifier($table).' WHERE '.$db->quoteIdentifier($col).'='.$db->quoteSmart($val)); -- paperCrane --Justin Patrin--

« previous php.pear.general (#14805) next »