fix: SQL injection :clown:

This commit is contained in:
2024-04-25 16:22:56 +02:00
parent e15b6a10bf
commit 686058d025

View File

@@ -11,8 +11,10 @@ if ($_SERVER["REQUEST_METHOD"] == "POST") {
$name = $_POST['name']; $name = $_POST['name'];
$message = $_POST['message']; $message = $_POST['message'];
$sql = "INSERT INTO " . $config['DB_NAME'] . " (name, message) VALUES ('$name', '$message')"; $sql = "INSERT INTO " . $config['DB_NAME'] . " (name, message) VALUES (?, ?)";
mysqli_query($conn, $sql); $stmt = mysqli_prepare($conn, $sql);
mysqli_stmt_bind_param($stmt, "ss", $name, $message);
mysqli_stmt_execute($stmt);
header("Location: " . $_SERVER['PHP_SELF']); header("Location: " . $_SERVER['PHP_SELF']);
exit; exit;