> >  It's already been escaped, $business is pulled out of the database
> >  after they log in. :)
>     I don't care, Prune.
>     (I still get a kick out of knowing that.  Who was it, Jochem or
> Zoltan who said that?  ;-P)

/me points at Jochem ;)

Zoltán Németh

>     NEVER trust that the data is escaped regardless of where it
> originated.  Supposed someone else writes a script to tie into your
> database and doesn't escape it, and Hagar The Horrible's
> great-great(^15) grandson, Hacker The Horndog comes in and finds the
> vulnerability, and enters the company name as "';DELETE FROM current
> WHERE 1;SELECT * FROM current WHERE 1 "?
>     Bye, data.
>     Learn: http://xkcd.com/327/
