[TYPO3-german] Crossite Scripting t3lib_div::_POST('variable')

Georg Ringer news at ringerge.org
Thu Jul 1 10:31:43 CEST 2010


Am 01.07.2010 10:28, schrieb Chris Bernhard:
>         return mysql_real_escape_string($value);

resistent gegen beratung? ;)

nimm doch bitte $GLOBALS['TYPO3_DB']->fullQuoteStr($myPostVar, $tablename);

georg


More information about the TYPO3-german mailing list