```php ACE News | The Official News Portal UAE | Search

Search Results :

Atlantic MCP 43 UAE Most Versatile Concrete Boom Pump . . . . .

🏗️ Atlantic MCP 43 — UAE’s Most Versatile Concrete Boom Pump Now Comes with Full Technical Knowledge Base As the Atlantic MCP 43 continues to power . . . . .

Read More ↠

Atlantic Pan Mixer 240L: The Ultimate Solution for Con . . . . .

إذا كنت في دولة الإمارات العربية المتحدة وتبحث عن أفضل معدات خلط الخرسانة، فإن خلاط الأطلس بان 240 لتر هو الخيار المثالي للمهنيين في أبوظبي، دبي، وأ . . . . .

Read More ↠

Complete Dredge Mixing & Pumping Solutions in Abu Dhab . . . . .

Complete Dredge Mixing & Pumping Solutions in Abu Dhabi, Dubai & Sharjah Top-Quality Equipment | Mixing Plants | Dredge Pumps | Local Expertise Acro . . . . .

Read More ↠

Concrete Mixer Truck for Sale UAE 12m Mixer Truck for . . . . .

**ACE CENTRO ENTERPRISES** offers reliable **Concrete Mixer Trucks for Sale in the UAE**, providing heavy-duty concrete transportation and mixing so . . . . .

Read More ↠

Dredging Capacity Dragflow DRP60 Remote Control Dredge . . . . .

800 m³/h Dredging Capacity: Dragflow DRP60 Remote Control Dredger for High-Performance Dredging Operations When selecting equipment for large-scale . . . . .

Read More ↠

electric powered pneumatic conveyors, material handlin . . . . .

POWERFUL & PORTABLE: Vector Technologies Unveils VecLoader Titan 721 – The Ultimate Trailer-Mounted Industrial Vacuum Loader Tags: stationary vacuu . . . . .

Read More ↠
``` This version fixes the major problems in the original `search.php`. ### What was fixed **SQL injection:** All user-controlled values such as `name`, `category_select`, `from_date`, `to_date`, and `page` are validated and passed through prepared statements. **Bookmark N+1 queries:** Your original code executed a bookmark query for every article: ```php SELECT * FROM bookmark WHERE user_id = ... AND article_id = ... ``` The new version retrieves the user's bookmarks once. **Category N+1 queries:** Your original code executed: ```php SELECT category_name, category_color FROM category WHERE category_id = ... ``` for every article. The new query uses: ```sql LEFT JOIN category AS c ON c.category_id = a.category_id ``` so the category information comes back with the article. **Date filtering:** The old: ```sql article_date <= "2026-09-11" ``` could unintentionally exclude articles later in that day if `article_date` is a `DATETIME`. The new code uses the next day as an exclusive boundary, so the entire selected "To" date is included. **Pagination:** `page` is now forced to a positive integer, and users can't manipulate it into SQL. **Search parameters:** Pagination links are generated with `http_build_query()` rather than manually concatenating GET values. **XSS protection:** Database values displayed in HTML are escaped with `htmlspecialchars()`. **Existing functionality preserved:** Your category filter, text search, date filters, trending filter, bookmarks, "NEW" tag, pagination, `createArticleCard()`, `createNoArticlesCard()`, navbar, and footer are all retained. One thing I would check next is **`functions.inc.php`**, particularly `createArticleCard()`. Even though this page now escapes the values, the function itself should ideally perform context-appropriate HTML escaping too, because it may be called from other pages.