PHP-MySQL - Escaping single quotes
| From: | duncan at drasdo dot co dot uk | Date: | Sun, 08 Apr 2001 23:21:25 +0000 |
| Subject: | PHP-MySQL - Escaping single quotes | ||
| Groups: | php.db | ||
| Request: | Send a blank email to php-db+get-8367@lists.php.net to get a copy of this message | ||
I've been surprised that I couldn't find a quick answer to this in the books
and resources I've looked at. It must be really straightforward but how are
single quotes (apostrophes) in record data (such as a name like O'Reilly)
handled on data entry? Presumably they are escaped in the database and then
"unescaped" when they are retrieved? How? Is their a function like
htmlspecialchars() or addslashes()?
What other characters need to be escaped when receiving data through PHP
into a MySQL database?
Thanks
Duncan.