Código PHP:
function MakeMeSafe ($variable) {
$variable = trim(preg_replace(sql_regcase("/(from|select|insert|delete|where|drop table|show tables|#|\*|--|\\\\)/"),"",$variable));
$variable = stripslashes($variable);
$variable = strip_tags($variable);
$variable = mysql_real_escape_string($variable);
return $variable;
}
Un abrazo!