here’s a few resources that someone may find helpful:

and don’t forget that in php, variables like $_SERVER['REQUEST_URI'] and $_SERVER['HTTP_REFERER'] are user input.

I've been using PEAR DB's quoteSmart and escaping SQL wildcard characters when the input goes into a WHERE clause.

