Noname > 11-12-11, 01:49 AM
Noname > 24-04-12, 12:11 PM
$foruminid = $_REQUEST['listforumid'];
$foruminid = $db->escape_string(str_replace("'","",str_replace('"',"",stripslashes($_REQUEST['listforumid']))));
Noname > 25-04-12, 04:10 AM
//killchar
function killchar($sInput)
{
$badChars = array("select", "drop", ";", "--", "insert", "delete", "xp_","#","*","'",'"',"union");
$size=count($badChars);
for($i=0;$i<$size;$i++)
$sInput=str_replace($badChars[$i],"",$sInput);
return $sInput;
}
//end killchar
$foruminid = $db->escape_string(str_replace("'","",str_replace('"',"",stripslashes($_REQUEST['listforumid']))));
$foruminid = $db->escape_string(killchar(stripslashes($_REQUEST['listforumid'])));
Noname > 01-05-12, 10:44 PM
Noname > 06-05-12, 03:07 PM
dcongphuc > 30-12-12, 02:30 PM
SystemTN > 12-07-13, 07:24 AM
Noname > 12-07-13, 12:16 PM
SystemTN > 12-07-13, 08:58 PM