If you are reading user input from a session, then you must sanitize it. If the user cannot influence the value (possibly a timestamp), there is no need to check it.
, , . html SQL. HTML-, htmlspecialchars(), MySQL MySql, mysql_real_escape_string().