function filtr($data) { $filter = array("select", "delete", "union", "update", "insert","\\", "'", ",", ";", "--", "-", "%20", "%27", " ", "`", "=", "%"); $filter_data = str_replace($filter, "", strtolower($data)); return $filter_data; } function sql($query = "", $param = array()) { if (!is_array($param) || count($param) == 0) { return mysql_query(filtr($query)); } else { foreach ($param as $key => $val) { $query = str_replace("{".$key."}", $val, $query); } return mysql_query(filtr($query)); } }