|
Posted by Geoff Berrow on 11/18/06 11:44
I'm doing some scripts for a co-located server. I notice that
magic_quotes_gpc is set to off on this installation.
Now, as a minimum, I run all user supplied data through
mysql_real_escape_string and check for newlines in header form fields
for mail scripts.
What other steps should I take?
--
Geoff Berrow (put thecat out to email)
It's only Usenet, no one dies.
My opinions, not the committee's, mine.
Simple RFDs http://www.ckdog.co.uk/rfdmaker/
Navigation:
[Reply to this message]
|