My book says prevent it like this:
$clean = array();
$mysql = array();
$clean['last_name']="o'reilly";
$mysql['last_name']=mysql_real_esc ape_string($cle an['last_name']);
why are we using an array ( $mysql['last_name'] ) instead of just a
variable: $val?
I just wanna understand. Thanks.
$clean = array();
$mysql = array();
$clean['last_name']="o'reilly";
$mysql['last_name']=mysql_real_esc ape_string($cle an['last_name']);
why are we using an array ( $mysql['last_name'] ) instead of just a
variable: $val?
I just wanna understand. Thanks.
Comment