function fldUpdate($fName, $fValue, $ftype, $endchar) {
$fValue = str_replace("'","''",$fValue);
$fValue = trim($fValue);
if ($ftype=='str') {
$upStr=$fName."='".$fValue."'".$endchar;
} else {
$upStr=$fName."=".$fValue.$endchar;
}
return $upStr;
}
function checkString($s, $endchar) {
$s = str_replace("'","''",$s);
$s = trim($s);
$s .= $endchar;
return $s;
}
function getRequest($fldStr) {
if (isset($_REQUEST[$fldStr])) {
$fldStr = stripslashes($_REQUEST[$fldStr]);
} else {
$fldStr='';
}
return $fldStr;
}
function getFormFld($fldStr) {
if (isset($_POST[$fldStr])) {
$fldStr = stripslashes($_POST[$fldStr]);
} else {
$fldStr='';
}
return $fldStr;
}
function sqlSanitize($fldStr) {
$fldStr = str_ireplace ('cmdshell','~',$fldStr);
$fldStr = str_ireplace ('cast(','~',$fldStr);
$fldStr = str_ireplace ('+as+','~',$fldStr);
$fldStr = str_ireplace ('+or+','~',$fldStr);
$fldStr = str_ireplace ('@@','~',$fldStr);
$fldStr = str_ireplace ('drop ','~',$fldStr);
$fldStr = str_ireplace ('alter ','~',$fldStr);
$fldStr = str_ireplace ('exec ','~',$fldStr);
$fldStr = str_ireplace ('insert ','~',$fldStr);
$fldStr = str_ireplace (' union ','~',$fldStr);
$fldStr = str_ireplace ('executesql','~',$fldStr);
$fldStr = str_ireplace ('|','~',$fldStr);
$fldStr = str_ireplace ('@@','~',$fldStr);
return $fldStr;
}
?>