note 33106 deleted from function.html-entity-decode by sniper
| From: | sniper@php.net | Date: | Tue, 21 Oct 2003 09:54:14 +0000 |
| Subject: | note 33106 deleted from function.html-entity-decode by sniper | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-58982@lists.php.net to get a copy of this message | ||
Note Submitter: thebitman@attbi.com
----
not sure about this, but I think that this'll work:
$sql_safe = addslashes(html_entity_decode(stripslashes($_POST['data1'])))
this is for the case of, for example, you want a dropdown-menu selection (so need
htmlspecialchars()), but of course you dont trust people to actually use the form when they could
just POST you whatever they want using telnet