Changed database access to PDO using prepared statements
This commit is contained in:
@@ -74,9 +74,6 @@ function sanitize($input) {
|
||||
// convert special chars
|
||||
$input = htmlentities($input,ENT_QUOTES,'UTF-8');
|
||||
|
||||
// make sql ready
|
||||
$input = mysqli_real_escape_string($dblink, $input);
|
||||
|
||||
// and return
|
||||
return $input;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user