} else {
// Old way with enterable two-char-code
$countryRow = "country";
- $countryData = addslashes(substr($_POST['cntry'], 0, 2));
+ $countryData = substr($_POST['cntry'], 0, 2);
}
//////////////////////////////
VALUES ('%s','%s','%s','%s','%s',%s,'%s','%s',%s, %s,%s,'%s',%s, %s,'%s','UNCONFIRMED','%s','%s', UNIX_TIMESTAMP(), UNIX_TIMESTAMP()".$ADD2.")",
array(
$countryRow,
- SQL_ESCAPE(substr($_POST['gender'], 0, 1)),
- SQL_ESCAPE($_POST['surname']),
- SQL_ESCAPE($_POST['family_name']),
- SQL_ESCAPE($_POST['street_nr']),
+ substr($_POST['gender'], 0, 1),
+ $_POST['surname'],
+ $_POST['family_name'],
+ $_POST['street_nr'],
$countryData,
bigintval($_POST['zip']),
- SQL_ESCAPE($_POST['city']),
- SQL_ESCAPE($_POST['addy']),
+ $_POST['city'],
+ $_POST['addy'],
bigintval($_POST['day']),
bigintval($_POST['month']),
bigintval($_POST['year']),