[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: DB_eSession deleteSession() SQL injection
- To: bugtraq@xxxxxxxxxxxxxxxxx
- Subject: Re: DB_eSession deleteSession() SQL injection
- From: interact@xxxxxxxxxxxxxxxxxx
- Date: 1 May 2006 22:07:04 -0000
I think the solution below is a better and safer approach.
replace addslashes() with mysql_real_escape_string()
$_sess_id_set = ( empty($_sess_id_set) ) ? NULL:
mysql_real_escape_string($_sess_id_set);