Forum Moderators: coopster
function tep_sanitize_string($string) {
$patterns = array ('/ +/','/[<>]/');
$replace = array (' ', '_');
return preg_replace($patterns, $replace, trim($string));
} $name = mysql_real_escape_string($_POST['name']); $strip = mysql_real_escape_string($_POST['name']); mysql_query('SELECT * FROM names WHERE name LIKE "'.$strip%'"');