View Single Post
Old 11-02-2011, 07:08 PM  
potter
Confirmed User
 
Industry Role:
Join Date: Dec 2004
Location: Denver
Posts: 6,559
Quote:
Originally Posted by BestXXXPorn View Post
All these people offering advice and nobody points out to you that you have a giant gaping massive security hole... never, Never, NEVER use GET or POST variables right in a fucking SQL statement...
Yeah, I was pretty shocked too.

Code:
$page = mysql_escape_string($_GET['page']);
In fact, I'd probably even set it as an INT as well.
__________________

potter is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote