For Programmers: Free Programming Magazines  


Home > Archive > PHP Documentation > September 2004 > cvs: phpdoc /en/reference/mysql/functions mysql-real-escape-string.xml









You are viewing an archived Text-only version of the thread. To view this thread in it's original format and/or if you want to reply to this thread please [click here]

 

Author cvs: phpdoc /en/reference/mysql/functions mysql-real-escape-string.xml
Aidan Lister

2004-09-29, 8:04 pm

aidan Wed Sep 29 11:12:42 2004 EDT

Modified files:
/phpdoc/en/reference/mysql/functions mysql-real-escape-string.xml
Log:
Reverting, bug #30274 is simply not true

http://cvs.php.net/diff.php/phpdoc/...17&r2=1.18&ty=u
Index: phpdoc/en/reference/mysql/functions/mysql-real-escape-string.xml
diff -u phpdoc/en/reference/mysql/functions/mysql-real-escape-string.xml:1.17 phpdoc/en/reference/mysql/functions/mysql-real-escape-string.xml:1.18
--- phpdoc/en/reference/mysql/functions/mysql-real-escape-string.xml:1.17 Wed Sep 29 07:52:42 2004
+++ phpdoc/en/reference/mysql/functions/mysql-real-escape-string.xml Wed Sep 29 11:12:42 2004
@@ -1,5 +1,5 @@
<?xml version="1.0" encoding="iso-8859-1"?>
-<!-- $Revision: 1.17 $ -->
+<!-- $Revision: 1.18 $ -->
<!-- splitted from ./en/functions/mysql.xml, last change in rev 1.100 -->
<refentry id="function.mysql-real-escape-string">
<refnamediv>
@@ -88,7 +88,7 @@

// We didn't check $_POST['password'], it could be anything the user wanted! For example:
$_POST['username'] = 'aidan';
-$_POST['password'] = "' OR ''='";
+$_POST['password'] = "' OR 1=1";

// This means the query sent to MySQL would be:
echo $query;
Sponsored Links







Also available: Server administration forum archive | Web Design forum archive | Software forum archive | Hardware reviews archive

Copyright 2008 codecomments.com