Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.php > #3257

Re: PHP/MySQL oddity

Path csiph.com!x330-a1.tempe.blueboxinc.net!usenet.pasdenom.info!weretis.net!feeder4.news.weretis.net!newsfeed.straub-nv.de!uucp.gnuu.de!newsfeed.arcor.de!newsspool2.arcor-online.net!news.arcor.de.POSTED!not-for-mail
Content-Type text/plain; charset="UTF-8"
Message-ID <4486353.dkDdi1TLyq@PointedEars.de> (permalink)
From Thomas 'PointedEars' Lahn <PointedEars@web.de>
Reply-To Thomas 'PointedEars' Lahn <php@PointedEars.de>
Organization PointedEars Software (PES)
Date Sun, 02 Oct 2011 04:30:10 +0200
User-Agent KNode/4.4.11
Content-Transfer-Encoding 8Bit
Subject Re: PHP/MySQL oddity
Newsgroups comp.lang.php
References <n6le87lkemajdupb9d24qn811ult5t4dm1@4ax.com> <us2kl8-apa.ln1@luuk.invalid.lan> <ej1f87d8q3kh47e3bf45okpiv8t4doc9dn@4ax.com> <4e8792f1$0$31289$a8266bb1@newsreader.readnews.com>
Followup-To comp.lang.php
MIME-Version 1.0
Lines 102
NNTP-Posting-Date 02 Oct 2011 04:30:11 CEST
NNTP-Posting-Host 3b8ae76c.newsspool1.arcor-online.net
X-Trace DXC=dN_iha?Z>Qd;iVb[J9ZZP`ic==]BZ:afn4Fo<]lROoRa<`=YMgDjhgb3:^P=7BE@=`DZm8W4\YJNlb@mF9jNikde_dXMBNGELEalK4k@m_^g4e
X-Complaints-To usenet-abuse@arcor.de
Xref x330-a1.tempe.blueboxinc.net comp.lang.php:3257

Followups directed to: comp.lang.php

Show key headers only | View raw


Denis McMahon wrote:

> On Sat, 01 Oct 2011 17:31:38 -0400, Mason Barge wrote:
>> On Sat, 01 Oct 2011 20:31:31 +0200, Luuk <Luuk@invalid.lan> wrote:
>>> On 01-10-2011 20:14, Mason Barge wrote:
>>>> <form name=...><input type=text . . . value = '<?php echo $info;?>'
>>> After PHP is done, and when $info contains "some'text" (without the
>>> double-quotes) What would you guess to be send to your browser?
>>>
>>> Indeed, it's:
>>> <form name=...><input type=text . . . value = 'some'text'.....
>> 
>> Thank you very much.
>> 
>> Changed it to value=\"$info\"
> 
> You need to understand where and when to use the escape functions.
> 
> Specifically, when using text that was supplied by the user in any sql
> statement, use e.g:
> 
> <?php
> 
> if (isset($_POST['fieldname']))
>   {
>   $fielddata = mysql_real_escape_string($_POST['fieldname']);
>   }
> else
>   {
>   $fielddata = "some_default_value";
>   }
> 
> $sql = "UPDATE tablename SET fieldname = '{$fielddata}' WHERE
> _condition_";

This approach fails for

  $fielddata = "That's my default";

And let us hope that the default value is not, e. g. because of an 
accidental copy & paste operation, 

  $fielddata = "That'; DROP TABLE tablename; …";

It is a good idea to always escape values in database queries.

It is an even better idea to use prepared statements to do that only when 
necessary and in the way required by the used DBMS.  MySQLi and PDO are 
among the DBA PHP modules which support this.

  $mysqli = new Mysqli(…);
  $stmt = $mysqli->prepare(
    "UPDATE tablename SET fieldname=? WHERE foo = ?");
  $stmt->bind_param('ss', $fielddata, $condition);
  $stmt->execute();
  $stmt->close();

(If you do not like the object-oriented variant you can still use the simple 
functional variant.  Function identifiers would be `mysqli_prepare' and so 
forth.)

Using the mysqli module, and the corresponding MySQL versions, instead of 
mysql, and corresponding MySQL versions, is /*strongly*/ recommended:

<http://php.net/manual/en/mysqli.overview.php>

However, I prefer PDO as it is more flexible in terms of configuration and 
reuse:

  $pdo = new PDO(…);
  $stmt = $pdo->prepare(
    "UPDATE tablename SET fieldname=:fieldname WHERE foo = :condition");
  $stmt->execute(array(
    'fieldname' => $fielddata,
    'condition' => $condition
  ));
  $stmt->closeCursor();

(You can also still bind your parameters the mysqli way.)

<http://php.net/manual/en/book.pdo.php>

In Zend Framework it would be as simple as

  $db = new Zend_Db_Adapter_Pdo_Mysql(…);
  $db->update('tablename',
    array(
      'fieldname' => $fielddata
    ),
    array(
      'foo' => $condition
    ));

<http://framework.zend.com/apidoc/1.11/db_Db_Adapter_Pdo_Mysql.html#%5CZend_Db_Adapter_Pdo_Mysql>


PointedEars
-- 
    realism:    HTML 4.01 Strict
    evangelism: XHTML 1.0 Strict
    madness:    XHTML 1.1 as application/xhtml+xml
                                                    -- Bjoern Hoehrmann

Back to comp.lang.php | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

PHP/MySQL oddity Mason Barge <masonbarge@gmail.com> - 2011-10-01 14:14 -0400
  Re: PHP/MySQL oddity Luuk <Luuk@invalid.lan> - 2011-10-01 20:31 +0200
    Re: PHP/MySQL oddity Mason Barge <masonbarge@gmail.com> - 2011-10-01 17:31 -0400
      Re: PHP/MySQL oddity Denis McMahon <denismfmcmahon@gmail.com> - 2011-10-01 22:23 +0000
        Re: PHP/MySQL oddity Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2011-10-02 04:30 +0200
          Re: PHP/MySQL oddity Jerry Stuckle <jstucklex@attglobal.net> - 2011-10-02 09:55 -0400
  Re: PHP/MySQL oddity Arno Welzel <usenet@arnowelzel.de> - 2011-10-02 19:35 +0200

csiph-web