|
Posted by Toby A Inkster on 03/21/07 12:25
pradeep wrote:
> <option value=concat(concat(Fullname,','),id)>
<option value="concat(concat(Fullname,','),id)">
> $str="select fullname from test where ".$_REQUEST['fields']." like '%".
> $_REQUEST['input1']."%'";
That line just scared the bejeezus out of me!
Big, big security problem right here.
--
Toby A Inkster BSc (Hons) ARCS
Contact Me ~ http://tobyinkster.co.uk/contact
Geek of ~ HTML/SQL/Perl/PHP/Python*/Apache/Linux
* = I'm getting there!
Navigation:
[Reply to this message]
|