PHP , POST/GET, Magic Quotes. , SQL-.
, SQL- , . PHP .
PHP ! PHP.ini magic_quotes_gpc off, :
if (get_magic_quotes_gpc()) {
$process = array(&$_GET, &$_POST, &$_COOKIE, &$_REQUEST);
while (list($key, $val) = each($process)) {
foreach ($val as $k => $v) {
unset($process[$key][$k]);
if (is_array($v)) {
$process[$key][stripslashes($k)] = $v;
$process[] = &$process[$key][stripslashes($k)];
} else {
$process[$key][stripslashes($k)] = stripslashes($v);
}
}
}
unset($process);
}
: http://www.php.net/manual/en/security.magicquotes.disabling.php
, SQL-. , , . , , . - / .
- , , .
INSERT INTO someTable (field1, field2) VALUES (:field1, :field2);
:field1 :field2, . , . , (/ , ).
PHP - PDO. PDO , :
http://net.tutsplus.com/tutorials/php/why-you-should-be-using-phps-pdo-for-database-access/