I got a $_GET
and users are able to send the $_GET
string to the MySQL, so quick question:
Is this query:
mysql_query("SELECT XX FROM ZZ WHERE YY %LIKE% " . htmlspecialchars($_get['string']) . ";");
enough to be safe? or I should add something more than htmlspecialchars()
to be safe?
Thank you in advance for all replies.