dpglo66848 2015-04-10 07:30
浏览 37
已采纳

我是否需要准备和绑定$ _SESSION变量?

My question is simple, I have this session user:

$user = $_SESSION['user'];

and I want to do a select with it:

select * from online where user='$user' order by id desc LIMIT 1

Do I need to prepare a $_SESSION variable as I do with POST and GET? If I do not, is there a chance of SQL injection?

select * from online where user=? order by id desc LIMIT 1
  • 写回答

1条回答 默认 最新

  • dtbrd80422 2015-04-10 07:48
    关注

    1. Do I need to prepare a $_SESSION variable as I do with POST and GET?

    Yes you do. It's as unsafe as a normal bald $_POST and $_GET.

    2. If I do not, is there a chance of sql injection?

    There is such a thing as Session hijacking which makes (almost) everything possible with sessions. You definitely need to look into that. As I said before a Session is as unsafe as a $_POST and $_GET. So yes you have a chance of SQL injection.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥50 求解vmware的网络模式问题 别拿AI回答
  • ¥24 EFS加密后,在同一台电脑解密出错,证书界面找不到对应指纹的证书,未备份证书,求在原电脑解密的方法,可行即采纳
  • ¥15 springboot 3.0 实现Security 6.x版本集成
  • ¥15 PHP-8.1 镜像无法用dockerfile里的CMD命令启动 只能进入容器启动,如何解决?(操作系统-ubuntu)
  • ¥30 请帮我解决一下下面六个代码
  • ¥15 关于资源监视工具的e-care有知道的嘛
  • ¥35 MIMO天线稀疏阵列排布问题
  • ¥60 用visual studio编写程序,利用间接平差求解水准网
  • ¥15 Llama如何调用shell或者Python
  • ¥20 谁能帮我挨个解读这个php语言编的代码什么意思?