Re: Preventing SQL Injection/ Cross Site Scripting
| From: | Dotan Cohen | Date: | Sat, 21 Apr 2007 10:06:59 +0000 |
| Subject: | Re: Preventing SQL Injection/ Cross Site Scripting | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-253416@lists.php.net to get a copy of this message | ||
On 21/04/07, Leonard Burton <leonardburton@gmail.com> wrote:
Hi Dotan, Why not use mysql_escape_string()?I use mysql_real_escape_string() as the second to last function in there. Dotan Cohen http://dotancohen.com/eng/army_pictures.php http://lyricslist.com/lyrics/artist_albums/575/7a3.html