27.08.2018, 12:33
Apparently from what I've read and seen on the forums, you should be using escaped strings for anything a user can put in if it's going to the database, as they could put in the ' ending the string, and then run a code after to wipe your database clean.
What you need to look at though is escaped characters and such things.
What you need to look at though is escaped characters and such things.