25.01.2017, 12:15
Use a especific %e for users donґt send Escapes strings
Change
To
Change
PHP код:
mysql_format(MHandle, query, sizeof(query), "SELECT * FROM `accounts` WHERE `Name` = '%s' LIMIT 1", pname);
PHP код:
mysql_format(MHandle, query, sizeof(query), "SELECT * FROM `accounts` WHERE `Name` = '%e' LIMIT 1", pname);