Quote:
Originally Posted by MarcoH64
Change:
PHP Code:
$getuserid=$DB_site->query_first("SELECT userid FROM user WHERE username='$newusername'");
to:
PHP Code:
$getuserid=$DB_site->query_first("SELECT userid FROM user WHERE username='" . addslashes($newusername) . "'");
Do that everywhere the username is used in a query.
|
Should I go ahead and do
addslashes(htmlspecialchars($newusername)) for every occurence of
$newusername to be thorough?
Also wrestling with getting some kind of CSS to load.