Noname > 05-12-11, 04:14 AM
Noname > 24-04-12, 12:12 PM
Noname > 26-04-12, 12:38 AM
$foruminid = $_REQUEST['listforumid'];
$foruminid = explode(")",$db->escape_string(str_replace(" ",")",str_replace("'","",str_replace('"',"",stripslashes($mybb->input['listforumid']))))));
$foruminid = $foruminid[0];
}
Select mahocsinh,ho, ten from dshocsinh where mahocsinh= '$mahocsinh'
$mahocsinh='0025' union all mahocsinh,username,password from tblUser
Select mahocsinh,ho, ten from dshocsinh where mahocsinh= '0025' union all mahocsinh,username,password from tblUser
$mahocsinh= escape_string(str_replace(" ",")", $mahocsinh
$mahocsinh='0025')union)all)mahocsinh,username,password)from)tblUser
$mahocsinh=explode(")",$mahocsinh)
$mahocsinh[]="'0025',union,all,mahocsinh,username,password,from,tblUser"
$mahocsinh=$mahocsinh[0]
$mahocsinh='0025'