Re: does "quote" DB filter out all dubious characters preventing sql injection?

From: Date: Fri, 08 Oct 2004 12:04:21 +0000
Subject: Re: does "quote" DB filter out all dubious characters preventing sql injection?
References: 1 2 3  Groups: php.pear.general 
Request: Send a blank email to pear-general+get-14813@lists.php.net to get a copy of this message
Hi,
You forgot to point out another option: use placeholders. Read the PEAR::DB documentation regarding prepare and execute --
<snip>
And in the second one: $sth = $db->query('SELECT * FROM ? WHERE ? = ?', array($table, $col, $val)); If the values already contain their quotes (e.g., if magic_quotes is on), then PEAR::DB won't re-escape them; if not, it will escape them before placing them in the SQL.
correct me if I'm wrong, but I think the 2nd query should read $db->query('SELECT * FROM ! WHERE ? = ?', array($table, $col, $val)); with ! as the placeholder for the tablename, or it will be quoted using "string quotes". I don't think this would have the desired effect :) MySQL (for instance) req. backticks to quote a tablename. So quoteIdentifier() may still be necessary in this case (?) I must confess I (still) use DB 1.62, and this behavior may differ in later versions CirTap

« previous php.pear.general (#14813) next »