note 56271 deleted from function.mysql-real-escape-string by aidan

From: Date: Sat, 04 Feb 2006 12:06:36 +0000
Subject: note 56271 deleted from function.mysql-real-escape-string by aidan
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-102985@lists.php.net to get a copy of this message
Note Submitter: jesper at snt dot utwente dot nl ---- I use: <?php $username = ereg_replace("\\"|'| .*", "", $_POST["username"]); ?> This will remove all quotes and everything after the first whitespace. This will remove most SQL-injection vulnerabilities for variables which shouldn't allow whitespaces or quotes. (like usernames)

« previous php.notes (#102985) next »