```php ACE News | The Official News Portal UAE | Search

Search Results :

Heavy Duty Aquatic Weed Cutter Machine: Advanced Aquati . . . . .

Aquatic Harvesters for Powerful Waterway Management The demand for a Heavy Duty Aquatic Weed Cutter Machine has increased significantly as water bo . . . . .

Read More

Heavy Duty Canvas Tarp UAE Heavy Duty Canvas Tarpaulin . . . . .

Heavy Duty Canvas Tarp Supplier in UAE ACE Centro Enterprises supplies Heavy Duty Canvas Tarp and Canvas Tarpaulin in the UAE for construction, ind . . . . .

Read More

Heavy Duty Canvas Tarps UAE Canvas Tarp Supplier

Heavy Duty Canvas Tarps Supplier in UAE ACE Centro Enterprises supplies Heavy Duty Canvas Tarps in the UAE for construction, industrial, transporta . . . . .

Read More

Heavy Duty Cement Grout Pump, High Pressure Injection E . . . . .

Heavy Duty Cement Grout Pump ACE Centro Enterprises supplies robust heavy duty cement grout pump solutions engineered for continuous operation in d . . . . .

Read More

Heavy Duty Cement Grout Pump, Portable Grouting Equipme . . . . .

ACE CENTRO ENTERPRISES provides professional and reliable heavy duty cement grout pump, portable grouting equipment, and non-stop grout pumping system . . . . .

Read More

Heavy Duty Concrete Bucket Supplier in UAE & Middle Eas . . . . .

High-Performance Concrete Handling Solution for Demanding Construction Projects ACE Centro Enterprises is a leading supplier of Heavy Duty Concrete . . . . .

Read More
``` This version fixes the major problems in the original `search.php`. ### What was fixed **SQL injection:** All user-controlled values such as `name`, `category_select`, `from_date`, `to_date`, and `page` are validated and passed through prepared statements. **Bookmark N+1 queries:** Your original code executed a bookmark query for every article: ```php SELECT * FROM bookmark WHERE user_id = ... AND article_id = ... ``` The new version retrieves the user's bookmarks once. **Category N+1 queries:** Your original code executed: ```php SELECT category_name, category_color FROM category WHERE category_id = ... ``` for every article. The new query uses: ```sql LEFT JOIN category AS c ON c.category_id = a.category_id ``` so the category information comes back with the article. **Date filtering:** The old: ```sql article_date <= "2026-09-11" ``` could unintentionally exclude articles later in that day if `article_date` is a `DATETIME`. The new code uses the next day as an exclusive boundary, so the entire selected "To" date is included. **Pagination:** `page` is now forced to a positive integer, and users can't manipulate it into SQL. **Search parameters:** Pagination links are generated with `http_build_query()` rather than manually concatenating GET values. **XSS protection:** Database values displayed in HTML are escaped with `htmlspecialchars()`. **Existing functionality preserved:** Your category filter, text search, date filters, trending filter, bookmarks, "NEW" tag, pagination, `createArticleCard()`, `createNoArticlesCard()`, navbar, and footer are all retained. One thing I would check next is **`functions.inc.php`**, particularly `createArticleCard()`. Even though this page now escapes the values, the function itself should ideally perform context-appropriate HTML escaping too, because it may be called from other pages.