Re: Still struggling.....
am 18.02.2006 05:01:27 von zeldorblat
UKuser wrote:
> That is superb. After a few weeks I appear to be finally there! I am
> just working on linking my update button to a refresh option, as it
> won't refresh. But thanks a lot!
It doesn't refresh because you draw the HTML and then update the
database. Why not just update the database first?
Re: Still struggling.....
am 24.02.2006 00:20:06 von Jim Michaels
"UKuser" wrote in message
news:1140206022.118491.266180@f14g2000cwb.googlegroups.com.. .
> This code is still not working. I have adjusted it so the table
> displays however, what I'm after is that when you update any number of
> fields, and click update, the whole table gets updated.
>
> Also, what is the smallest code to add to avoid SQL/XSS injectiony
> stuff?
just google SQL Injection. here's one.
http://en.wikipedia.org/wiki/SQL_injection
this depends on that type in input string you've got. If the user is
putting in HTML and you know that, then of course you are going to have to
use maybe the first one here. the -- maybe a bad hair-trigger.
if (preg_match("/'\s*;/", $string) || preg_match("/--/",$string)) {
//lockout user or do something
}
or just ignore them:
$string=mysql_real_escape_string(str_replace(";","",$string) );
mysql_escape_string and its like do not handle semicolons, so that's the
reason for str_replace.
if you really want to avoid it, use mysqli functions and mysqli_prepare()
and use variable binding.
>
> Thanks
>
>
> test 4
>