19.11.2017, 10:42
Theoretically, can a name be used in injection if it contains only(usual name):
for example, query:
Код:
0-9, a-z, A-Z, [], (), $ @ . _ and = only
PHP код:
format(query, sizeof(query), "INSERT INTO `History` (`SomeName`) VALUES ('%s')", name);//name - got with GetPlayerName
mysql_tquery(mysql, query, "", 0);