in reply to Help make upload from web secure

As has been repeated many times by those wiser than I, when determining whether data is "safe" or appropriate for your database/process/input/output/whatever you shouldn't focus on what you don't want (back ticks, non-ASCII, non-numbers, whatever) but rather on what you DO want. It's easy to think of all the things that ARE acceptable... it's much harder to think of everything that ISN'T acceptable. Sure enough you're going to forget something. Heck, the technology could even change (UNICODE, for example). Make your programs filter by what is good not by what is bad.

Gary Blackburn
Trained Killer