RE: [PHP] SQL security
| From: | Chris W. Parker | Date: | Fri, 17 Oct 2003 16:08:18 +0000 |
| Subject: | RE: [PHP] SQL security | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-166487@lists.php.net to get a copy of this message | ||
Eugene Lee <mailto:list-php-1@fsck.net>
on Friday, October 17, 2003 8:20 AM said:
> If you're using MySQL, you can use mysql_real_escape_string(). If
> you're using another database, hopefully there is a similar function.
Doesn't MySQL automatically protect against attacks like SQL injection?
Or maybe it's that it automatically applies addslashes()? I can't
remember exactly.
c.
--
Don't like reformatting your Outlook replies? Now there's relief!
http://home.in.tum.de/~jain/software/outlook-quotefix/