View Single Post
Old 10-29-2008, 08:11 PM  
jimbona
Confirmed User
 
Join Date: Jan 2007
Posts: 190
Just took a look at the new zip ;)

Your search box can now only be a number as your run it with (int) and not mysql_real_escape_string() also want to add into to all ints to as a safe measure.

Might also want to protect those with register_globals on in functions/cookie.php
__________________
Thanks
Paul
Thunder-Ball.net - Member
jimbona is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote