le logiciel d'analyse nommé dans un précedent POST, ma dis que j'avais des failles de sécurité - Injection SQL -, est ce que quelqu'un saurait me dire comment y remédier.
Merci d'avance.
Bonne journée
Code
• Alimentation :
</td>
<td width="40%"> <select name="listbox_alim" style="width:600px;">
<option name="alim" value="alim" >Aucun(e)</option>
<?php
$req = "select distinct * from products p, products_description pd, products_to_categories p2c, categories_description cd where p.products_status = '1' and p.products_id = pd.products_id and p.products_id = p2c.products_id and p2c.categories_id = cd.categories_id and cd.categories_id LIKE '1658' order by p.products_price ASC ";
$sql = mysql_query($req);
while ($data = mysql_fetch_assoc($sql))
{
$nom_alim = $data['products_name'];
$prix_alim = round($data['products_price'] * 1.196, 2);
$id_alim = $data['products_id'];
echo "<option value=$id_alim> ".($nom_alim)." - ".($prix_alim)." €</option>";
}
?>
</select>
</td>
</tr>
<tr>
<td width="60%" style="font-size:12px">
</td>
<td width="40%"> <select name="listbox_alim" style="width:600px;">
<option name="alim" value="alim" >Aucun(e)</option>
<?php
$req = "select distinct * from products p, products_description pd, products_to_categories p2c, categories_description cd where p.products_status = '1' and p.products_id = pd.products_id and p.products_id = p2c.products_id and p2c.categories_id = cd.categories_id and cd.categories_id LIKE '1658' order by p.products_price ASC ";
$sql = mysql_query($req);
while ($data = mysql_fetch_assoc($sql))
{
$nom_alim = $data['products_name'];
$prix_alim = round($data['products_price'] * 1.196, 2);
$id_alim = $data['products_id'];
echo "<option value=$id_alim> ".($nom_alim)." - ".($prix_alim)." €</option>";
}
?>
</select>
</td>
</tr>
<tr>
<td width="60%" style="font-size:12px">