mysql_query("INSERT INTO user_badges (user_id, badge_id)
VALUES ('". $_SESSION['user']['id'] ."',VIP)");
How can I make this safe?
mysql_query("INSERT INTO user_badges (user_id, badge_id)
VALUES ('". $_SESSION['user']['id'] ."',VIP)");
How can I make this safe?
Use newer functions like mysqli_query
or even better PDO library
.
Bind params, do not inject them in query.
Sanitize your params.
Read: