
Originally Posted by
vern
On a side note, I hope you seriously aren't using $_POST directly.
mao...
vulnerable kaayo na ug sql injection...
here's a sample code to prevent your page from sql injection
PHP Code:
if(get_magic_quotes_gpc()) {
$product_name = stripslashes($_POST['product_name']);
$product_description = stripslashes($_POST['product_description']);
}
else {
$product_name = $_POST['product_name'];
$product_description = $_POST['product_description'];
}
// Make a safe query
$query = sprintf("INSERT INTO products (`name`, `description`, `user_id`) VALUES ('%s', '%s', %d)",
mysql_real_escape_string($product_name),
mysql_real_escape_string($product_description),
$_POST['user_id']);