I have a lot of user inputs from $_GET and $_POST... At the moment I always write mysql_real_escape_string($_GET[\'var\'])..
$_GET
$_POST
mysql_real_escape_string($_GET[\'var\'])
I
real_escape_string($var); $var = sanitizeString($var); return $var; } ?>