. "" , .
"" - . , , , . , $_POST SQL-, HTML - XSS. , , MIME, , . , - Kiddy , " " , .
, ( ), . , PHP . , , , , script. - . , ( , , "log.txt", - ).
... ? -
include('log.txt');
- "" , . , , - <?php exec('rm -rf /') ?> .
- , PHP magic_quotes. PHP (WRONGLY STUPIDLY) , , , SQL SQL , . , , escape-. , , MySQL, , , , SQL Server? PHP Miles O\'Brien Miles O''Brien, UNDO , PHP .
TL; DR: , / . , .