Re: Preventing SQL Injection/ Cross Site Scripting

From: Date: Mon, 23 Apr 2007 14:37:08 +0000
Subject: Re: Preventing SQL Injection/ Cross Site Scripting
References: 1 2 3  Groups: php.general 
Request: Send a blank email to php-general+get-253526@lists.php.net to get a copy of this message
On 4/23/07, WeberSites LTD <berber@weber-sites.com> wrote:
I'm trying to understand from the examples why anyone that has get_magic_quotes_gpc() returning true would need to use stripslashes() and then mysql_real_escape_string(). wouldn't that just add slashes to the same places? berber
Yes, sort of... mysql_real_escape_string() considers character sets before escaping. There is a difference.

« previous php.general (#253526) next »