>>12
these are the same people who think it's a good idea to build SQL statements by string concatenation, and add new functions like mysql_real_escape_string instead of just fixing or replacing the broken mysql_escape_string function they already have. what do you think they're going to do?