dpglo66848 2015-04-09 23:30
浏览 37
已采纳

我是否需要准备和绑定$ _SESSION变量?

My question is simple, I have this session user:

$user = $_SESSION['user'];

and I want to do a select with it:

select * from online where user='$user' order by id desc LIMIT 1

Do I need to prepare a $_SESSION variable as I do with POST and GET? If I do not, is there a chance of SQL injection?

select * from online where user=? order by id desc LIMIT 1
  • 写回答

1条回答 默认 最新

  • dtbrd80422 2015-04-09 23:48
    关注

    1. Do I need to prepare a $_SESSION variable as I do with POST and GET?

    Yes you do. It's as unsafe as a normal bald $_POST and $_GET.

    2. If I do not, is there a chance of sql injection?

    There is such a thing as Session hijacking which makes (almost) everything possible with sessions. You definitely need to look into that. As I said before a Session is as unsafe as a $_POST and $_GET. So yes you have a chance of SQL injection.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论
编辑
预览

报告相同问题?