Basically, what I want to do is this:
mysql_query("SELECT ... FROM ... ORDER BY $_GET[order]")
They can obviously easily create a SQL error by putting non-sense in there, but mysql_query only allows you to execute 1 query, so they can't put something like 1; DROP TABLE ....
Is there any damage a malicious user could do, other than creating a syntax error?
If so, how can I sanitize the query?
There's a lot of logic built on the $_GET['order'] variable being in SQL-like syntax, so I really don't want to change the format.
To clarify, $_GET['order'] won't just be a single field/column. It might be something like last_name DESC, first_name ASC.