Security

    Date: 04/01/05 (PHP Community)    Keywords: mysql, html, sql

    I’m working on some code and I am trying to make sure all the incoming data is secure. I currently call mysql_real_escape_string()
    on all incoming data, but I am wondering if it would be worth my while to call htmlspecialchars() on it as well. Does anyone else have any good tips on un-tainting user data.

    Source: http://www.livejournal.com/community/php/279632.html

« PEAR question || MySQL - Selecting based... »


antivirus | apache | asp | blogging | browser | bugtracking | cms | crm | css | database | ebay | ecommerce | google | hosting | html | java | jsp | linux | microsoft | mysql | offshore | offshoring | oscommerce | php | postgresql | programming | rss | security | seo | shopping | software | spam | spyware | sql | technology | templates | tracker | virus | web | xml | yahoo | home