--- "M. Sokolewicz" <tularis@xxxxxxx> wrote: (http://www.php.net/manual/en/function.mysql-real-escape-string.php) I have my eye on example 3: The Quote_Smart function. Do I have to list all the variables out though or is there a way to have it check everything passing through ? What would nice is if I didn't have to put the Quote_smart function in every query statement but have it test everything? Stuart > > -- PHP General Mailing List (http://www.php.net/) To unsubscribe, visit: http://www.php.net/unsub.php