Noname > 05-12-11, 04:14 AM
Noname > 24-04-12, 12:12 PM
Noname > 26-04-12, 12:38 AM
$foruminid = $_REQUEST['listforumid']; 
$foruminid = explode(")",$db->escape_string(str_replace(" ",")",str_replace("'","",str_replace('"',"",stripslashes($mybb->input['listforumid']))))));
                    $foruminid = $foruminid[0];
                    
                    } 
Select mahocsinh,ho, ten from dshocsinh where mahocsinh= '$mahocsinh'$mahocsinh='0025' union all mahocsinh,username,password from tblUser 
Select mahocsinh,ho, ten from dshocsinh where mahocsinh= '0025' union all mahocsinh,username,password from tblUser 
$mahocsinh= escape_string(str_replace(" ",")", $mahocsinh 
$mahocsinh='0025')union)all)mahocsinh,username,password)from)tblUser 
$mahocsinh=explode(")",$mahocsinh) 
$mahocsinh[]="'0025',union,all,mahocsinh,username,password,from,tblUser" 
$mahocsinh=$mahocsinh[0] 
$mahocsinh='0025'