Solved

PHP/MySQL Query and SQL Injection

Posted on 2010-09-07
4
381 Views
Last Modified: 2013-12-13
Is this a really bad query?

SELECT * FROM categories WHERE categoryID = 5

Could something like this leave me vulnerable to SQL Injection?  How do I prevent it?  I'm using Dreamweaver to create my PHP pages and then customizing when necessary.  
0
Comment
Question by:ssailer
  • 2
4 Comments
 
LVL 24

Accepted Solution

by:
slyong earned 400 total points
ID: 33618731
Well the query itself is not vulnerable to SQL Injection.  However, if you are doing your PHP like this:

$query = "SELECT * FROM categories WHERE categoryID = " . $catID;

There is a possibility that someone put in a query string to do the injection.  A fast way to prevent SQL injection would be:

$catID = mysql_real_escape_string($catID);
$query = "SELECT * FROM categories WHERE categoryID = " . $catID;

0
 

Author Comment

by:ssailer
ID: 33618760
So, if I enter a fixed value, instead of a parameter, it should be okay?
0
 
LVL 24

Expert Comment

by:slyong
ID: 33618907
Yup
0
 
LVL 3

Assisted Solution

by:ncollings
ncollings earned 100 total points
ID: 33618919
If the query is hard coded in your php and non of the parameters come from the browser then it would be very difficult to exploit.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Part of the Global Positioning System A geocode (https://developers.google.com/maps/documentation/geocoding/) is the major subset of a GPS coordinate (http://en.wikipedia.org/wiki/Global_Positioning_System), the other parts being the altitude and t…
Creating and Managing Databases with phpMyAdmin in cPanel.
Explain concepts important to validation of email addresses with regular expressions. Applies to most languages/tools that uses regular expressions. Consider email address RFCs: Look at HTML5 form input element (with type=email) regex pattern: T…
This tutorial will teach you the core code needed to finalize the addition of a watermark to your image. The viewer will use a small PHP class to learn and create a watermark.

943 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

6 Experts available now in Live!

Get 1:1 Help Now