- How to prevent URL blind sql injection attack
- www.site.com/phpfile.php?1d=1
- www.site.com/phpfile.php
- www.site.com/phpfile.php?1d=1
- $id = intval($_GET['id']);
- if(is_numeric($_GET['id'])){
- $id = mysql_real_escape_string($_GET['id']);
- }
- else{
- ;///////display error
- }