note 56271 deleted from function.mysql-real-escape-string by aidan
| From: | aidan@php.net | Date: | Sat, 04 Feb 2006 12:06:36 +0000 |
| Subject: | note 56271 deleted from function.mysql-real-escape-string by aidan | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-102985@lists.php.net to get a copy of this message | ||
Note Submitter: jesper at snt dot utwente dot nl
----
I use:
<?php
$username = ereg_replace("\\"|'| .*", "",
$_POST["username"]);
?>
This will remove all quotes and everything after the first whitespace. This will remove most
SQL-injection vulnerabilities for variables which shouldn't allow whitespaces or quotes. (like
usernames)