Re: does "quote" DB filter out all dubious characters preventing sql injection?
| From: | CirTap | Date: | Fri, 08 Oct 2004 12:04:21 +0000 |
| Subject: | Re: does "quote" DB filter out all dubious characters preventing sql injection? | ||
| References: | 1 2 3 | Groups: | php.pear.general |
| Request: | Send a blank email to pear-general+get-14813@lists.php.net to get a copy of this message | ||
Hi,
You forgot to point out another option: use placeholders. Read the PEAR::DB documentation regarding prepare and execute --<snip>
And in the second one: $sth = $db->query('SELECT * FROM ? WHERE ? = ?', array($table, $col, $val)); If the values already contain their quotes (e.g., if magic_quotes is on), then PEAR::DB won't re-escape them; if not, it will escape them before placing them in the SQL.correct me if I'm wrong, but I think the 2nd query should read $db->query('SELECT * FROM ! WHERE ? = ?', array($table, $col, $val)); with ! as the placeholder for the tablename, or it will be quoted using "string quotes". I don't think this would have the desired effect :) MySQL (for instance) req. backticks to quote a
tablename.
So quoteIdentifier() may still be necessary in this case (?)
I must confess I (still) use DB 1.62, and this behavior may differ in later versions
CirTap