note 50513 deleted from security.database.sql-injection by bjori
| From: | bjori@php.net | Date: | Wed, 12 Apr 2006 15:01:47 +0000 |
| Subject: | note 50513 deleted from security.database.sql-injection by bjori | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-107886@lists.php.net to get a copy of this message | ||
Note Submitter: programmer at umistudio dot com
----
I think, this small script can be usefull against sql-injections.
<?
function ekran($var) {
if(is_array($var) != 1) {
if($var != mysql_real_escape_string($var))
error_inform();
return mysql_real_escape_string($var);
}
else
return array_filter($var);
}
function check_params() {
array_filter($_GET, "ekran");
array_filter($_POST, "ekran");
array_filter($_COOKIE, "ekran");
}
@import_request_variables("CGP", "");
?>
you can define "error_inform()" function to log(or send mail) abnormal values.