The Student Room Group

Does anyone know how to sanitise a variable?

$message = $_POST{'message'};
$message = escape_tags ($message)
insertIntoDatabase($message);

Someone posted this as an answer before but I don't know where to put it, anyone have an idea?

Quick Reply