Thread: SQL Injection
View Single Post
Old 06-25-2008, 08:46 PM   #5 (permalink)
maZtah
The Acquainted
 
Join Date: Oct 2007
Posts: 126
Thanks: 12
maZtah is an unknown quantity at this point
Default

Just a little note: with mysql you don't have to put quotes around integers. So user_group = %d will do the job, no need to put quotes around it!

Futhermore, it looks quite safe to me.


Edit:
Wildhoney won the race to mention about the quotes. ;)
maZtah is offline  
Reply With Quote