Because $searchterm is user-supplied, I could supply O'Reilly to break your SQL query or 1; delete from users -- to wipe all users from the user table or 1; update users set is_admin=1 -- to make all accounts administrator accounts.
Interpolating user-supplied data into SQL statements is a problematic thing and best avoided.
In reply to Re^11: CGI Action call
by Corion
in thread CGI Action call
by tultalk
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |