Jump to content

Question on mySQL injection


Shadowing

Recommended Posts

been wondering about this for a while

do I need to put the escape on each WHERE? or do i really only need to put it on the $_POST

i can probably understand why i need it on $_GET also after WHERE. So wondering about the session id.

 

 <?php mysql_query("UPDATE systems SET homes=  $homes + '".mysql_real_escape_string($_POST['homes'])."' 

WHERE address = '".mysql_real_escape_string($_GET['planet'])."' AND id = '".($_SESSION['user_id'])."'"); ?> 

Link to comment
https://forums.phpfreaks.com/topic/254472-question-on-mysql-injection/
Share on other sites

  Quote

been wondering about this for a while

do I need to put the escape on each WHERE? or do i really only need to put it on the $_POST

i can probably understand why i need it on $_GET also after WHERE. So wondering about the session id.

 

 <?php mysql_query("UPDATE systems SET homes=  $homes + '".mysql_real_escape_string($_POST['homes'])."' 

WHERE address = '".mysql_real_escape_string($_GET['planet'])."' AND id = '".($_SESSION['user_id'])."'"); ?> 

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.