Re: SQL Injections
| From: | Eugene Lee | Date: | Fri, 07 Nov 2003 10:29:15 +0000 |
| Subject: | Re: SQL Injections | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-168820@lists.php.net to get a copy of this message | ||
On Fri, Nov 07, 2003 at 09:43:20AM -0000, Shaun wrote:
:
: does anyone know of a function i can include in my scrpits to ensure all
: $_POST values sent from a page don't include any SQL?
If you're using MySQL, look at mysql_escape_string().