Re: sql injection and php

From: Florian Weimer (Weimerat_private-Stuttgart.DE)
Date: Wed May 29 2002 - 02:54:19 PDT

  • Next message: Sverre H. Huseby: "Re: sql injection and php"

    Jacek Lach <jlachat_private> writes:
    
    > Does the magic_quotes in php's configuration resolves the problem of sql 
    > injection?
    
    It depends.  If your database uses the same escaping strategy as PHP,
    it may be safe.
    
    -- 
    Florian Weimer 	                  Weimerat_private-Stuttgart.DE
    University of Stuttgart           http://CERT.Uni-Stuttgart.DE/people/fw/
    RUS-CERT                          +49-711-685-5973/fax +49-711-685-5898
    



    This archive was generated by hypermail 2b30 : Wed May 29 2002 - 10:20:33 PDT