Link to home
Start Free TrialLog in
Avatar of citadelind
citadelindFlag for India

asked on

My SQL Injection in PHP

- Please give me solutions of SQL Injection in my project.

- It is again and again comes in database.

- Script add in every table in database.

- How to prevent this problem?

- Give me good solutions so that next do not happen.
Avatar of Loganathan Natarajan
Loganathan Natarajan
Flag of India image

do you use mysql_real_escape_string() function on your input?
something like this,

$unsafe_variable = $_POST["user-input"];
$safe_variable = mysql_real_escape_string($unsafe_variable);

mysql_query("INSERT INTO table (column) VALUES ('" . $safe_variable . "')");
ASKER CERTIFIED SOLUTION
Avatar of Ray Paseur
Ray Paseur
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of citadelind

ASKER

Thanks for help.