Check out Janggi (Korean Chess), our featured variant for December, 2024.


[ Help | Earliest Comments | Latest Comments ]
[ List All Subjects of Discussion | Create New Subject of Discussion ]
[ List Earliest Comments Only For Pages | Games | Rated Pages | Rated Games | Subjects of Discussion ]

Single Comment

PHP Functions[Subject Thread] [Add Response]
🕸Fergus Duniho wrote on Tue, Apr 24, 2018 03:25 PM UTC:

No, wait. Since the unpaired tail argument for table_row() and table_rows() is appended as is, this can be used for SQL injection. Therefore, this value should never be determined by user input.