Czekam na oceny.

firany-sklep.pl
<?php class security { function sql($value){ } else { } return $value; } function html($value) { return $value; } function addsql($value) { return $value; } function strip($value) { return $value; } function all($value) { return $value; } } ?>
$dane_login = $security->all($_POST['email']);
<?php class security { function sql($value){ } else { } return $value; } function html($value) { return $value; } function addsql($value) { return $value; } function strip($value) { return $value; } function all($value) { return $value; } } ?>
$dane_login = $security->all($_POST['email']);
$_POST['email'] = '123; DELETE FROM users'
function sql($value){ } else { } return $value; }
$s = new security; $id = $s->sql("0 OR 1=1"); $sql = "SELECT `superduper_user` from `t1` where id={$id}";
$s = new security; $id = $s->sql("0 OR 1=1"); $sql = "SELECT `superduper_user` from `t1` where id={$id}";
function add_sql_where($value){ $value = filter_var($value,FILTER_SANITIZE_NUMBER_INT); } else { $value = filter_var($value,FILTER_SANITIZE_NUMBER_INT); } return $value; } function add_sql_update($value){ } else { } return $value; } /////show_in_html
try{ $pdo = new PDO('mysql:host=localhost;dbname=firany;encoding=utf8', 'root', ''); } catch(PDOException $e){ } $res1 = $pdo->prepare('INSERT INTO `user` (`nick`) VALUES (`:nick`) ') $res1->bindValue(':nick', $_GET['nick'], PDD::PARAM_STR); $res1 ->execute(); $res1 ->closeCursor(); $res2 = $pdo -> query('SELECT `nick` FROM `user`'); while ($row = $res ->fetch()) { } $res2 ->execute(); $res2 ->closeCursor();