in reply to Re^10: CGI Action call
in thread CGI Action call
Because $searchterm is user-supplied, I could supply O'Reilly to break your SQL query or 1; delete from users -- to wipe all users from the user table or 1; update users set is_admin=1 -- to make all accounts administrator accounts.
Interpolating user-supplied data into SQL statements is a problematic thing and best avoided.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^12: CGI Action call
by tultalk (Monk) on Mar 20, 2018 at 11:28 UTC | |
by poj (Abbot) on Mar 20, 2018 at 11:41 UTC | |
by davies (Monsignor) on Mar 20, 2018 at 12:59 UTC |