Jump to content
  • 0

About escape_sql


lakasmonk

Question


  • Group:  Members
  • Topic Count:  33
  • Topics Per Day:  0.01
  • Content Count:  231
  • Reputation:   24
  • Joined:  12/18/11
  • Last Seen:  

how to use escape_sql

the flux donation redeemer uses escape_sql command script

i dont know how to fix the bug?

if you want i can post ss

Link to comment
Share on other sites

1 answer to this question

Recommended Posts


  • Group:  Members
  • Topic Count:  7
  • Topics Per Day:  0.00
  • Content Count:  130
  • Reputation:   43
  • Joined:  12/11/11
  • Last Seen:  

'escape_sql()' is used on string variables, like '@password$', you want to use within the 'query_sql()' command

Whenever you let the user provide information that will be used in the database, you should escape it.

What it does: It makes sure the input is safe from injections, more info on wikipedia

Example:

The user inputs: Injecting code "+DELETE...+"
escape_sql("Injecting code "+DELETE...+"");
And it will become: Injecting code "+DELETE...+"

And if you have a bug, you should provide more information regarding the bug.

  • Upvote 1
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Answer this question...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...