in reply to Win32 taint...shouldn't this fail?
"
...
If a value is not given in the query string, as in the queries ``name1=&name2='' or ``name1&name2'', it will be returned as an empty string. This feature is new in 2.63.
...
"
So, as you don't give any value to the param 'comment'
$comment = param('comment');
|
|---|