Board index   FAQ   Search  
Register  Login
Board index PHP PHP Scripts

database variable

Links for php scripts

Moderators: macek, egami, gesf

Re: database variable

Postby Redcircle » Wed Mar 26, 2008 2:36 pm

because $group is not defined in the function you would have to either define it our pass it into the function.

function displayUsers($group){

}

also I'd recommend to escape the string to avoid sql injections. see mysql_real_escape_string
$q = "SELECT username,userlevel,email,group FROM ".TBL_USERS." WHERE user= '".mysql_real_escape_string($group)."'";

unless you know for a fact that $group is sanitized you should use mysql_real_escape_string() on any variable that you have gotten from the user. Trusted or not.
User avatar
Redcircle
Moderator
Moderator
 
Posts: 830
Joined: Tue Jan 21, 2003 10:42 pm
Location: Michigan USA

Return to PHP Scripts

Who is online

Users browsing this forum: No registered users and 1 guest

Sponsored by Sitebuilder Web hosting and Traduzioni Italiano Rumeno and antispam for cPanel.