Path: csiph.com!x330-a1.tempe.blueboxinc.net!usenet.pasdenom.info!news.albasani.net!eternal-september.org!feeder.eternal-september.org!.POSTED!not-for-mail From: Arno Welzel Newsgroups: comp.lang.php Subject: Re: i getting this warning Date: Thu, 17 Nov 2011 15:15:14 +0100 Organization: A noiseless patient Spider Lines: 52 Message-ID: <4EC516F2.9070703@arnowelzel.de> References: <616578.124.1321442274513.JavaMail.geo-discussion-forums@prmf13> <4ec3d299$0$28440$a8266bb1@newsreader.readnews.com> <4EC50CA0.9090009@arnowelzel.de> Mime-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Injection-Info: mx04.eternal-september.org; posting-host="dd4uQGf4fHOQcq7/hg1u1Q"; logging-data="30866"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+kLPw+l/qrgLLXID/jzzR4B0qp7rZqyAc=" User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20111105 Thunderbird/8.0 In-Reply-To: Cancel-Lock: sha1:Xi4ULycHz29CWDCK4I+xIu/OpUg= Xref: x330-a1.tempe.blueboxinc.net comp.lang.php:3815 Jerry Stuckle, 2011-11-17 15:01: > On 11/17/2011 8:31 AM, Arno Welzel wrote: >> Denis McMahon, 2011-11-16 16:11: >> >>> On Wed, 16 Nov 2011 06:56:21 -0500, Jerry Stuckle wrote: >>> >>>> On 11/16/2011 6:17 AM, sri kanth wrote: >>> >>>>> $qs=$_REQUEST['id']; >>>>> $data=mysql_query("select * from tbl_porduct where pid=$qs"); >>> >>>> Three things. >>> >>> You missed "using unescaped user input in a query with no validation or >>> verification". I know it's only a select, but would you bet that he's >>> that sloppy with selects and yet rigorous with data changing statements? >> >> It does not matter what statement there *is*. Using data from outside in >> this way makes *everything* possible - this is the typical mistake which >> makes SQL injection possible! >> >> >> Example: >> >> Lets assume $qs is "1;drop tlb_product". >> >> $data = mysql_query("select * from tbl_product where pid=$qs"); >> >> The statement will be expanded to: >> >> "select * from tbl_product where pid=1;drop tbl_product" >> >> The result will be, that the table tbl_product will be dropped, if the >> MySQL user has the right to drop tables. >> >> > > > The statement will fail because mysql_query() will not execute multiple > statements in a single query. Generally and in this specific case you are right - but it is possible and you should never rely on this behaviour. See also: -- Arno Welzel http://arnowelzel.de http://de-rec-fahrrad.de