if you put everything into single quotes and mysql_real_escape string then there cant be done much wrong.
like
same with inserts and updates
or use intval() for integer values
like
PHP Code:
$sql = "select from users where username = '".mysql_real_escape_string($username)."' ";
or use intval() for integer values
PHP Code:
$sql = "select from users where id = '".intval($id)."' ";
Comment