Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 7620889
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 31, 20262026-05-31T04:03:32+00:00 2026-05-31T04:03:32+00:00

Im using the following code $query = SELECT * FROM raids WHERE RaidNum =

  • 0

Im using the following code

$query = "SELECT * FROM raids WHERE RaidNum = '".$_GET["RaidNum"]."'";

which catches from /raiddisplay.php?RaidNum=r75

My question is this entirely safe? can the value be exploited in some way to do something nasty and is there ways in which you can cleanse it. I tried to lookup up example usage of it but most were horribly complex and i really didn’t know where to start with it. Basically i want to make sure that somebody doesn’t purposely put in a value into the browser address bar that could have nasty adverse effects

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-31T04:03:34+00:00Added an answer on May 31, 2026 at 4:03 am

    It is entirely not safe. Let’s assume I visited /raiddisplay.php?RaidNum=';drop%20table%20raids;--, then I would effectively drop your table instead of reading a record.

    The best solution is to use prepared statements. Some may suggest to use mysql_real_escape_string, but even that is old and cumbersome. Although it is safe in itself, you must remember to always apply it. Using prepared statements with parameters or use a library that creates the statements for you, you are always safe.

    I think the easiest way to use this feature, is to use PDO, or PHP Data Objects.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I'm using the following code to query a database from my jsp, but I'd
I'm pulling a joined query from the DB using the following code: $query =
Currently I using the following code to get my JSON output from MySQL. <?php
I am using the following SQL query: Select * from table1 as t1, table2
I have the following code: Query query = this.getSession().createSqlQuery(select * from db@server:table where 1=1);
I am using the following code: $result = mysql_query(SELECT * FROM table LEFT JOIN
i'm using the following code: $select = SELECT * FROM MyTable; $export = mysql_query
I'm using the following code to load a grayscale JPG image, and query a
I'm trying to code the following HQL query using the Criteria API: var userList
I am using following code to remove some specific nodes from xml file..It show

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.