Re: does "quote" DB filter out all dubious characters preventing sql injection?

From: Date: Fri, 08 Oct 2004 18:14:20 +0000
Subject: Re: does "quote" DB filter out all dubious characters preventing sql injection?
References: 1 2 3 4 5 6  Groups: php.pear.general 
Request: Send a blank email to pear-general+get-14820@lists.php.net to get a copy of this message
Actually, to work it should be: $db->query('SELECT * FROM ! WHERE ! = ?', array($table, $col, $val));
oops :) yep, I overlooked the 2nd ? in your example :)
I've submitted a feature request for this. http://pear.php.net/bugs/bug.php?id=2483
excellent, let's see if they implement it. However, in my "career" as a PHP/SQL developer I only ran once into the situation where I had a table column named after an identifier (according to SQL92, AFAIK). It was: "type" MySQL didn't case when it was used like SELECT id, type FROM sometable so why bother with backticks? ;) I use ! in one of my recent (mysql-only) apps where I need to work with a zillion possible (3rd party app's) table prefixes at once like in 'SELECT c.foo, t.bar FROM ! as c, ! as t',
    array($tbl_c, $tbl_t)
For my MySQL only app I could use some ugly array("$tbl_c", "$tbl_t") but I doubt it's worth the additional characters ... I'd rather see multiple connection support in DB, so I can connect to different DBs and servers [PHP 4.2+] I'll check if there's a request for that. Have fun, CirTap

« previous php.pear.general (#14820) next »