Re: addslashes vs. mysql_real_escape_string
| From: | Justin Patrin | Date: | Mon, 19 Apr 2004 17:08:14 +0000 |
| Subject: | Re: addslashes vs. mysql_real_escape_string | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-183825@lists.php.net to get a copy of this message | ||
John W. Holmes wrote:
From: "Hardik Doshi" <php_hardik@yahoo.com>You may also want to look into quoteIdentifier for table and column names as well. -- paperCrane <Justin Patrin>Currently i am using PEAR DB abstration layer. Which function should i use to escape the ' character? There are couple of functions in the PEAR DB documentation so i don't know which one should i use.I don't use PEAR DB, but it looks like quoteSmart() is what I'd use. ---John Holmes...