I was testing a clients’ queries and came across an interesting question. Could a bad intentioned hacker SQL inject the following query:
SELECT * FROM mytable WHERE 1
AND cfield='0'
AND (
field1 like '%$searchterm%' OR
field2 like '%$searchterm%' OR
)
For example, to my mind, there’s no way he can comment out what’s after the first $searchterm, and just insert other queries:
field1 like '%$searchterm%'
Still, I may be wrong. Looking forward to your opinions. Thank you in advance!
1 Answer