Quote:
Originally posted by Velocd
What comes to my mind ofcourse is malicious users making PHP queries in the field and corrupting my database! Totally possible from my point of view. Other things include calling variables from the global.php, since it is being referenced in members.php, and also calling other variables from members.php
|
Well that's not possible, not if you escape the variable properly. But that's the least of your problems... I say drop it. People can use HTML in there that could redirect your users to their own Web site, and even worse, send the viewer's cookie data to their own server.