Re: database injection



Cujo wrote:
Peter van Schie wrote:

Take a look at mysql_real_escape_string.

Why are you assuming he is using mysql ?


True in most cases:
$db = (!empty(mentioned_db())) ? mentioned_db() : 'MySQL';

Grtz,
--
Rik Wasmus


.