Jump to content

Recommended Posts

Hi,

not sure if this should be in the php or mysql section..

I'm just wondering what kind of things I should do to make sure that inputs from a form are safe to put into a mysql table?

I'm currently using ereg() on an input to make sure that only numbers are entered, but on other forms I've got thiongs such as names and other details. How do I make sure that they're not going to break my table?

 

Thanks

//removing quotes from inputs
function quote($value)
{
if (get_magic_quotes_gpc()) {
	$value = stripslashes($value);
}

if (!is_numeric($value)) {
	$value = "'" . mysql_real_escape_string($value) . "'";
}

return $value;
}

this is a function i once got from somebody else, preventing people to try and get information from your database tables by entering ''s and what not... (there's a specific term for this, but i forgot it :P)

This thread is more than a year old. Please don't revive it unless you have something important to add.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.