JQUERY AJAX
var action="G3DKisVzJmPZa8c7nKTHJkqEmtSezwLNF3FVquwsNMi05OGkhNIdigm/EDUndoROtGQgmugg568OidxYzB5eJ5e9CAcrahEBBNcARkfMdy5givNlXsyPjTA4ulBRsGap|VjZgMVTK7unm+YL+b4lAfECAVwKePb/R6etD95oGAbw=";
var table="LWwkQy/JbJl959qQn/1jAZ+wwsz4qlGXJmN0P1/3/2maJCug+rh5RB2TmgriPxX1iVRKSXoWFQefvfRgFjMb0ys4YLQty10Xnqi1ubO+JfrrZ8fuEGu6DGmWNHuVhwCU|aV7uxHNJGmJ08wk0dzRhJcfT1COXHWJSKmtO3KHclLA=";
var fields="PatIyJMBdUYsR87bLwlVaar7xnPOkMaqq1o/WEnQNwJrurySi2jZO66Y0iQube4WTUaBork1PELJ94xqBU8oPMQz7+CZWBum9oeJpsVS+3CXAx6bmDCf08EDXz8x/4m1trs8CLA7ihhBYAeJVb93i+Giszp72pZsOQreYhmE12A=|cFOi51p8JRNFDSjUlQB2mtrt6P/1mVsNpqEBR+5QWxQ=";
var params=Yer+","+Tabaghat_From+","+Tabaghat_To+","+Mabna;
$.ajax({
url : "ajax/operationAJAX.php",
type: "POST",
data : {action:action,table:table,fields:fields,params:params},
success: function(response, textStatus, jqXHR)
{
if($.trim(response)!="empty")
{
TShowMessage("tblMessage",response);
}
else
TShowMessage("tblMessage","error:fail to insert data");
},
error: function (jqXHR, textStatus, errorThrown)
{
alert("error"+textStatus);
}
});
PHP
$action=mc_decrypt($_POST["action"]) ;
if($action=="delete")
{
//Table name
if(isset($_POST["table"]) && !empty($_POST["table"]))
$table=mc_decrypt($_POST["table"] ) ;
else
die('table name does not define');
//===================
//parameters
if(isset($_POST["params"]) && !empty($_POST["params"]))
$params=explode(',',$_POST["params"] );
else
die('parameters does not define');
//===================
//where
if(isset($_POST["where"]) && !empty($_POST["where"]))
$where=mc_decrypt($_POST["where"] );
else
die('where does not define');
//===================
$delete=$dbHandle->delet($table,$params,$where);
if(!empty($delete))
{
echo "data deleted!";
}
else
{
echo "empty";
}
}
i use AES encryption and encrypt action,TableName,FieldTable,Params,Where and send to server and in server base on action execute insert sql,select sql,delete sql,update sql.
**question:**Is this a security risk?
Would someone be able to use this information to perform illegal operation on the DB?
deletmethod actually do with the provided parameter values?