?
Solved

PHP/MySQL Query and SQL Injection

Posted on 2010-09-07
4
Medium Priority
?
389 Views
Last Modified: 2013-12-13
Is this a really bad query?

SELECT * FROM categories WHERE categoryID = 5

Could something like this leave me vulnerable to SQL Injection?  How do I prevent it?  I'm using Dreamweaver to create my PHP pages and then customizing when necessary.  
0
Comment
Question by:ssailer
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 24

Accepted Solution

by:
slyong earned 1600 total points
ID: 33618731
Well the query itself is not vulnerable to SQL Injection.  However, if you are doing your PHP like this:

$query = "SELECT * FROM categories WHERE categoryID = " . $catID;

There is a possibility that someone put in a query string to do the injection.  A fast way to prevent SQL injection would be:

$catID = mysql_real_escape_string($catID);
$query = "SELECT * FROM categories WHERE categoryID = " . $catID;

0
 

Author Comment

by:ssailer
ID: 33618760
So, if I enter a fixed value, instead of a parameter, it should be okay?
0
 
LVL 24

Expert Comment

by:slyong
ID: 33618907
Yup
0
 
LVL 3

Assisted Solution

by:ncollings
ncollings earned 400 total points
ID: 33618919
If the query is hard coded in your php and non of the parameters come from the browser then it would be very difficult to exploit.
0

Featured Post

Secure Your WordPress Site: 5 Essential Approaches

WordPress is the web's most popular CMS, but its dominance also makes it a target for attackers. Our eBook will show you how to:

Prevent costly exploits of core and plugin vulnerabilities
Repel automated attacks
Lock down your dashboard, secure your code, and protect your users

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When table data gets too large to manage or queries take too long to execute the solution is often to buy bigger hardware or assign more CPUs and memory resources to the machine to solve the problem. However, the best, cheapest and most effective so…
In this article, I’ll talk about multi-threaded slave statistics printed in MySQL error log file.
The viewer will learn how to dynamically set the form action using jQuery.
In this video, Percona Solutions Engineer Barrett Chambers discusses some of the basic syntax differences between MySQL and MongoDB. To learn more check out our webinar on MongoDB administration for MySQL DBA: https://www.percona.com/resources/we…
Suggested Courses

765 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question