SQL Injection

Users submit queries through your forms that execute scripts against your database.

  1. Escape form input before saving to db (addslashes)
  2. Don't build queries dynamically (use stored procedures or adodb.php, etc)
  3. Validate forms on the server
example
Next