Advertisement
reenadak

Preventing SQL injection

Aug 2nd, 2018
280
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 0.63 KB | None | 0 0
  1. //prevent injection
  2.     function qry($query) {
  3. // Connect to database
  4.       $this->dbconnect();
  5.  
  6. // get function arguments.
  7.       $args  = func_get_args();
  8.  
  9. // Get first argument.
  10.       $query = array_shift($args);
  11.  
  12.  
  13.       $query = str_replace("?", "%s", $query);
  14.       $args  = array_map('mysql_real_escape_string', $args);
  15.       array_unshift($args,$query);
  16.       $query = call_user_func_array('sprintf',$args);
  17.       $result = mysql_query($query) or die(mysql_error());
  18.           if($result){
  19.             return $result;
  20.           }else{
  21.              $error = "Error";
  22.              return $result;
  23.           }
  24.     }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement