Hi, I have some SQL injection vulnerability here and I’m wondering how to solve this problem.
if(isset($_POST['submit'])){
$sid = $_POST['sid'];
$token = $_POST['token'];
$to_number = $_POST['to-number'];
$from_number = $_POST['from-number'];
$text = $_POST['message'];
mysqli_query($con, "DELETE FROM sms_form");
mysqli_query($con, "DELETE FROM text1");
mysqli_query($con, "INSERT INTO sms_form SET
sid='$sid',
token='$token',
to_number='$to_number',
from_number='$from_number'
");
$id = mysqli_insert_id($con);
mysqli_query($con, "INSERT INTO text1 SET s_id=$id, text='$text'");
header("location:smsform.php");
exit();
}
$result = mysqli_query($con, "SELECT * FROM sms_form ORDER by id DESC");
$row = mysqli_fetch_array($result);
$chk_res = mysqli_query($con, "SELECT * FROM text1");
$chk_row = mysqli_fetch_array($chk_res);