RE: [PHP] Quotes in GET variables
| From: | Boget, Chris | Date: | Mon, 21 May 2001 14:01:39 +0000 |
| Subject: | RE: [PHP] Quotes in GET variables | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-53715@lists.php.net to get a copy of this message | ||
> Anyway, it's not a big thing if you're _really_ stringent about how you
> check every single variable which is used in a database query,
> system/passthru/exec, or eval command, and your checking methods are
> flawless, but otherwise it's just best to go to the trouble of hacking
> around the input explicitly.
What would you do to go about doing this? How can you be
_really stringent_ in checking your variables? Check that they
have a value?
Chris