SQL injection is already handled within the code by specific php calls, regex, and other means. There is nothing from the url that touches the database without first being cleaned in some manor. and even then, the software uses its own means to trigger SQL interactions, rather than relying on what is coming from URLs.


Current developer of UBB.threads PHP Forum Software
Current Release: UBBT 7.7.5 // Preview: UBBT 8.0.0
isaac @ id242.com // my forum @ CelicaHobby.com