I've experimented with a variation of this.
Something like ...
foreach($_REQUEST as $k=$v) {
$REQUEST[$k] = mysql_real_escape_string($v);
}
$query = "INSERT INTO table VALUES('$REQUEST[email]', '$REQUEST[name]')";
Problem is, this only works if you don't plan on modifying any of the values before you stick them in the database.You could also do something like ...
$query = "INSERT INTO table VALUES('{$e('email')}', '{$e('email')}')";
$e = 'esc';
function esc($v) {
mysql_real_escape_string($v);
}
But I think that looks pretty ugly.