SQL Injection
$txtUserId = $_GET("UserId");
$txtSQL = "SELECT * FROM Users WHERE UserId = " . $txtUserId;
UserId=105;%20DROP%20TABLE%20Suppliers
SELECT * FROM Users WHERE UserId = 105; DROP TABLE Suppliers;
방어법
$stmt = $dbh->prepare("INSERT INTO Customers (CustomerName,Address,City)
VALUES (:nam, :add, :cit)");
$stmt->bindParam(':nam', $txtNam);
$stmt->bindParam(':add', $txtAdd);
$stmt->bindParam(':cit', $txtCit);
$stmt->execute();
//$sql = "SELECT * FROM SQL_Injection WHERE type='".$_GET['type']."'";
$sql = "SELECT * FROM SQL_Injection WHERE type='".mysql_real_escape_string($_GET['type'])."'";
SELECT * FROM SQL_Injection WHERE type='public\' or 1=\'1'
ref