I have a lot of user inputs from $_GET
and $_POST
... At the moment I always write mysql_real_escape_string($_GET[\'var\'])
..
I
i used that pass array or get , post
function cleanme(&$array)
{
if (isset($array))
{
foreach ($array as $key => $value)
{
if (is_array($array[$key]))
{
secure_array($array[$key]);
}
else
{
$array[$key] = strip_tags(mysql_real_escape_string(trim($array[$key])));
}
}
}
}
Usage :
cleanme($_GET);
cleanme($_POST);