$value) { if (is_array($value)) { // Recursivamente escapa elementos si el valor es otro array $escapedData[$key] = escapeInputArray($value, $connection); } else { // Escapa el valor si no es un array $escapedData[$key] = $connection->real_escape_string($value); } } return $escapedData; } // Aplicar a $_POST y $_GET $_POST = escapeInputArray($_POST, $con); $_GET = escapeInputArray($_GET, $con); if (isset($_POST['countryId']) && !empty($_POST['countryId'])) { // Fetch state name base on country id mysqli_query($con,'SET NAMES utf8'); $query = "SELECT * FROM reeco_ssubcate2 WHERE id_cat = ".$_POST['countryId']." order by subcategoria ASC"; $result = $con->query($query); if ($result->num_rows > 0) { echo ''; while ($row = $result->fetch_assoc()) { echo ''; } } else { echo ''; } } elseif(isset($_POST['stateId']) && !empty($_POST['stateId'])) { $ktrajo=$_POST['stateId']; // Fetch city name base on state id mysqli_query($con,'SET NAMES utf8'); $query = "SELECT * FROM reeco_ssubcate3 WHERE id_subcat = ".$_POST['stateId']." order by subcat3 ASC"; $result = $con->query($query); if ($result->num_rows > 0) { echo ''; while ($row = $result->fetch_assoc()) { echo ''; } } else { echo ''; } } //'.$ktrajo.' ?>