Hello, i tried to escape outputed database plain
string using htmlenties as below
I tried it this way but is not working
below is entire code
please can someone help me to fix this htmlentities issues and check also if this code is sql vulnerable since the query is passed directly to database