simple script to prevent SQL injection in PHP

Just a very simple script to prevent SQL injection in PHP. Just add this directly after your database connector is created in your connection file (I assume you just include/require this so it is not written everywhere).

//This stops SQL Injection in POST vars 

foreach ($_POST as $key => $value) {
$_POST[$key] = mysql_real_escape_string($value);

//This stops SQL Injection in GET vars
foreach ($_GET as $key => $value) {
$_GET[$key] = mysql_real_escape_string($value);

Using the logic that $_POST and $_GET are arrays, this simply iterates through each key=>value pair and re-assigns the value as mysql_real_escape_string($value) with the same key. By putting this script straight after your connection, it is only run when safe data is required and is sure to catch and secure all values.


