Jump to content

Make data safe to input to mysql database


Dragen

Recommended Posts

Hi,

not sure if this should be in the php or mysql section..

I'm just wondering what kind of things I should do to make sure that inputs from a form are safe to put into a mysql table?

I'm currently using ereg() on an input to make sure that only numbers are entered, but on other forms I've got thiongs such as names and other details. How do I make sure that they're not going to break my table?

 

Thanks

//removing quotes from inputs
function quote($value)
{
if (get_magic_quotes_gpc()) {
	$value = stripslashes($value);
}

if (!is_numeric($value)) {
	$value = "'" . mysql_real_escape_string($value) . "'";
}

return $value;
}

this is a function i once got from somebody else, preventing people to try and get information from your database tables by entering ''s and what not... (there's a specific term for this, but i forgot it :P)

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.