SQL注入

Drupal sql 注入研究


  function debug_sql(string $type) {
    $list = [];
    $sql = <<<sql
SELECT node.nid AS nid, node.title AS title, node.created AS node_created
FROM 
{node} node
WHERE (( (node.status = '1') AND (node.type IN  ('$type')) ))
ORDER BY node_created DESC
sql;
    $result = db_query($sql);