3 ms·
Any method that doesn't open you up to remote code execution exploits is an improvement over that.
by alcari 13y ago
Any method that doesn't open you up to remote code execution exploits is an improvement over that.
- code_duck 13y agoLeveraging grep was my point, not that this would actually be code I'd use. Let's assume the line before that was getting $terms out of the query and sanitizing it. I suppose that doubles the length of my solution, though!
- jrockway 13y agoAh yes, php_real_escape_grep_parameters(3).
- code_duck 13y agoFiltering out all characters other than ASCII alphabetical with preg_replace would probably do it. And yeah, I'm not a huge fan of php - or the ridiculous function names it is known for. However, it can be dead simple to set up for trivial tasks (which is about all od want to use it for).