Re: [GENERAL] Reordering results for a report - Mailing list pgsql-php

From Tino Wildenhain
Subject Re: [GENERAL] Reordering results for a report
Date
Msg-id 3FDD789A.7060201@wildenhain.de
Whole thread Raw
In response to Re: [GENERAL] Reordering results for a report  ("scott.marlowe" <scott.marlowe@ihs.com>)
List pgsql-php
Hi Scott,

scott.marlowe schrieb:
[...]
>
> print "<url goes here...>?orderby=".$flds[$i]."moreurlstuffhere???";
>
> Then, if the orderby is set when you build your query, just append it:
>
> if (isset($orderby)){
>   $query.= "order by ".$orderby"
> }
>
> Add some directional control:
>
> if (isset($dir)){
>   if ($dir=="down") $query.=" DESC";
> }
>
[...]

This leads to a nice SQL-injection posibility.
At least it has to made sure that no illegal
data can be transported via $orderby

Regards
Tino


pgsql-php by date:

Previous
From: Gerard Samuel
Date:
Subject: Re: [PHP-DB] pg_result_error()
Next
From: "1M4M M4L1K"
Date:
Subject: export table stucture