somewhere during my studies, I learned something interesting .. He says something like the following:
$query = sprintf("SELECT firstname, lastname, address, age FROM friends
WHERE firstname='%s' AND lastname='%s'",mysql_real_escape_string($firstname),
mysql_real_escape_string($lastname));
using this query, not
$query="select firstname, lastname, address, age FROM friends
WHERE firstname='".$_RETURN['name1']."', lastname='".$_RETURN['name2']."'";
it seems reasonable .. you have ever tried this encoding .. and how it helps prevent any malicious attacks.
source
share