Re: Preventing SQL Injection/ Cross Site Scripting
| From: | Eric Butera | Date: | Mon, 23 Apr 2007 14:37:08 +0000 |
| Subject: | Re: Preventing SQL Injection/ Cross Site Scripting | ||
| References: | 1 2 3 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-253526@lists.php.net to get a copy of this message | ||
On 4/23/07, WeberSites LTD <berber@weber-sites.com> wrote:
I'm trying to understand from the examples why anyone that has get_magic_quotes_gpc() returning true would need to use stripslashes() and then mysql_real_escape_string(). wouldn't that just add slashes to the same places? berberYes, sort of... mysql_real_escape_string() considers character sets before escaping. There is a difference.