RE: [PHP] how to handle inserting special characters into a mysql field
| From: | Jay Blanchard | Date: | Fri, 14 Dec 2007 15:19:04 +0000 |
| Subject: | RE: [PHP] how to handle inserting special characters into a mysql field | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-265870@lists.php.net to get a copy of this message | ||
[snip]
I'm going to be inserting data from a PHP form into a mysql field. The
data could contain special characters like < > ' " \ /, etc. How do I
handle that? just $data = addslashes(htmlspecialchars($data)); before
the insert query? because later on the data will be read back from the
mysql db and I don't want it to contain a special character that would
break the PHP script.
[/snip]
I would use http://us3.php.net/mysql_real_escape_string