| 
	
 | 
 Posted by Geoff Berrow on 06/17/06 11:44 
I'm doing some scripts for  a co-located server.  I notice that 
magic_quotes_gpc  is set to off on this installation. 
 
Now, as a minimum, I run all user supplied data through 
mysql_real_escape_string and check for newlines in header form fields 
for mail scripts. 
 
What other steps should I take? 
 
 
--  
Geoff Berrow (put thecat out to email) 
It's only Usenet, no one dies. 
My opinions, not the committee's, mine. 
Simple RFDs http://www.ckdog.co.uk/rfdmaker/
 
  
Navigation:
[Reply to this message] 
 |