|
Posted by Geoff Berrow on 03/29/06 15:33
Message-ID: <V0tWf.18925$%d.8259@tornado.socal.rr.com> from Larry
contained the following:
>I guess I'm back to stripping all the special characters out before they get
>put into the database. Hmmmm...
No, you don't need to do that.
Just use htmlentities($sting, ENT_QUOTES)
But I'll echo the other concerns about security...
--
Geoff Berrow (put thecat out to email)
It's only Usenet, no one dies.
My opinions, not the committee's, mine.
Simple RFDs http://www.ckdog.co.uk/rfdmaker/
Navigation:
[Reply to this message]
|