addslashes vs. mysql_real_escape_string
| From: | Richard Davey | Date: | Sun, 18 Apr 2004 10:29:56 +0000 |
| Subject: | addslashes vs. mysql_real_escape_string | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-183759@lists.php.net to get a copy of this message | ||
Hi,
I just finished reading Chris Shiflett's article in this months php|a
about SQL injection and have a question I can't seem to find answered
anywhere:
Does mysql_real_escape_string (or mysql_escape_string) do anything
extra that addslashes() doesn't? In the examples in the manual it is
just used to escape the ' character, but that is exactly what
addslashes() will do anyway.
Is mysql_real_escape_string tolerant of magic quotes? i.e. will you
end up with double-quoted strings like: "it\\'s a lovely day" if you
call it too many times?
--
Best regards,
Richard Davey
http://www.phpcommunity.org/wiki/296.html