Is there a catchall function somewhere that works well for sanitizing user input for SQL injection and XSS att