Re: SQL Injections
| From: | Marek Kilimajer | Date: | Fri, 07 Nov 2003 11:16:34 +0000 |
| Subject: | Re: SQL Injections | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-168826@lists.php.net to get a copy of this message | ||
If you delete all reserved words from a string then this sentence would become:
you reserved words a this sentence would become :)
You want to ensure the incoming variables are not INTERPRETED as sql. Properly escape and quote the input.
Shaun wrote:
Hi, does anyone know of a function i can include in my scrpits to ensure all $_POST values sent from a page don't include any SQL? Thanks for your help