Reply to Re: Inserting NULL Integer Values

Your name:

Reply:


Posted by Bogdan Ribic on 10/20/51 11:30

Oliver Grätz wrote:
> Shaun schrieb:
>
>>$qid = mysql_query('INSERT INTO MYTABLE (
>> column1,
>> column2,
>> ) VALUES (
>> "'.$value1.'",
>> "'.$value2.'"
>> )');
>
>
> A bit off-topic but important: Always make sure that you check the
> contents of $value1 and $value2 before putting them into the query!
> With
>
> $value1 = 'xyz","xyz"); DELETE FROM MYTABLE;';
>
> you might get surprising results!
>
> This is called SQL injection and it's important to escape all the values
> before putting them into the statement.


Did you try that? This doesn't work on my machine:

mysql_query("DELETE FROM mytable; DELETE FROM mytable;");

ie, mysql extension won't let me do more than one statement at a time.

--

Open source PHP code generator for DB operations
http://sourceforge.net/projects/bfrcg/

[Back to original message]


Удаленная работа для программистов  •  Как заработать на Google AdSense  •  England, UK  •  статьи на английском  •  PHP MySQL CMS Apache Oscommerce  •  Online Business Knowledge Base  •  DVD MP3 AVI MP4 players codecs conversion help
Home  •  Search  •  Site Map  •  Set as Homepage  •  Add to Favourites

Copyright © 2005-2006 Powered by Custom PHP Programming

Сайт изготовлен в Студии Валентина Петручека
изготовление и поддержка веб-сайтов, разработка программного обеспечения, поисковая оптимизация