PHP protection of GET parameters
问题 OK consider this url: example.com/single.php?id=21424 It's pretty obvious to you and i that the PHP is going to take the id and run it through a mysql query to retrieve 1 record to display it on the page. Is there anyway some malicious hacker could mess this url up and pose a security threat to my application/mysql DB? Thanks 回答1: Of course, never ever ever consider a user entry (_GET, _POST, _COOKIE, etc) as safe. Use mysql_real_escape_string php function to sanitize your variables: http:/