RE: [PHP] Quotes in GET variables

From: Date: Mon, 21 May 2001 14:01:39 +0000
Subject: RE: [PHP] Quotes in GET variables
Groups: php.general 
Request: Send a blank email to php-general+get-53715@lists.php.net to get a copy of this message
> Anyway, it's not a big thing if you're _really_ stringent about how you > check every single variable which is used in a database query, > system/passthru/exec, or eval command, and your checking methods are > flawless, but otherwise it's just best to go to the trouble of hacking > around the input explicitly. What would you do to go about doing this? How can you be _really stringent_ in checking your variables? Check that they have a value? Chris

« previous php.general (#53715) next »