View Single Post
Old 09-14-2007, 01:59 PM   #3 (permalink)
baoh
The Visitor
 
Join Date: Sep 2007
Posts: 2
Thanks: 0
baoh is on a distinguished road
Default

Doesn't hurt to put single quotes around your escaped string either, even if you're inserting numbers. If you don't run it through sprintf, someone trying to cheat would just end up with a broken query since "id='5 OR id != 0'" doesn't exist.
baoh is offline  
Reply With Quote