dongxiqian2787 2011-08-29 22:07
浏览 7
已采纳

需要帮助改善PHP和MySQL的安全性[重复]

Possible Duplicate:
MySQL Syntax error. Can't solve it

Can anyone improve this code so it is secure and uses prepared statements?

$sql= "INSERT INTO users
(level,fname, mname, lname, dob, age, reg_date, phone, email, login, pwd, type, `group`, region, school, class, ip, subject, ban, university, profession, activation_code) 
VALUES 
('1','$data[fname]', '$data[mname]', '$data[lname]', '$dob', '$age', now(), '$data[phone]', '$email', '$login', '$pwd', '$type', '$group', '$region', '$school', '$class',  '$ip', '$subject', NULL, '$university', '$profession', '$activ_code')";
$result = $db->query($sql) or die(printf("Error: %s
", $db->error));
$id = $db->insert_id;  
$md5_id = md5($id);
$db->query("update users set md5_id='$md5_id' where id='$id'");
//  echo "<h3>Thank You</h3> We received your submission.";


?>
  • 写回答

2条回答 默认 最新

  • ds1379551 2011-08-29 22:31
    关注

    If we assume, that all the direct variables are filled with user-generated content, your code is wide open for sql injections. Instead, use a prepare statement and bind_param() to automatically set the correct security settings / escaping:

    $stmt = $dbh->prepare(
        "INSERT INTO REGISTRY (name, value) VALUES (:name, :value)");
    $stmt->bindParam('name', $name);
    $stmt->bindParam('value', $value);
    mysqli_stmt_execute($stmt);
    
    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论
查看更多回答(1条)

报告相同问题?

悬赏问题

  • ¥15 BP神经网络控制倒立摆
  • ¥20 要这个数学建模编程的代码 并且能完整允许出来结果 完整的过程和数据的结果
  • ¥15 html5+css和javascript有人可以帮吗?图片要怎么插入代码里面啊
  • ¥30 Unity接入微信SDK 无法开启摄像头
  • ¥20 有偿 写代码 要用特定的软件anaconda 里的jvpyter 用python3写
  • ¥20 cad图纸,chx-3六轴码垛机器人
  • ¥15 移动摄像头专网需要解vlan
  • ¥20 access多表提取相同字段数据并合并
  • ¥20 基于MSP430f5529的MPU6050驱动,求出欧拉角
  • ¥20 Java-Oj-桌布的计算