$sql = "INSERT INTO jos_uddeim (fromid, toid, message, datum) VALUES (".(int)$uid.", 84, ".$message.", ".(int)time().")";
Ensure that all text strings are "clean", so no SQL injection is possible.
Post edited by: slabbi, at: 2009/03/12 10:03
uddeIM & uddePF Development
CB Language Workgroup
CB 3rd Party Developer