Jump to content

php security issue.


zgkhoo

Recommended Posts

this is a function i run before i put anything into a sql query

<?php
function sql_safe($value) 
{
    if (get_magic_quotes_gpc()) 
    {
        $value = stripslashes($value);
    }
    if (!is_numeric($value) || $value[0] == '0')
    {
        $value = mysql_real_escape_string($value);
    }
    return $value;
}
?> 

i also run this function to what ever the user puts in:

$comment = htmlspecialchars($comment);

htmlspecialchars() takes away all the html characters read more about it here

http://za.php.net/manual/en/function.htmlspecialchars.php

 

also have a look here

http://www.talkphp.com/showthread.php?p=1804#post1804

Link to comment
https://forums.phpfreaks.com/topic/72163-php-security-issue/#findComment-363886
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.