RE: [PHP] how to handle inserting special characters into a mysql field

From: Date: Fri, 14 Dec 2007 15:19:04 +0000
Subject: RE: [PHP] how to handle inserting special characters into a mysql field
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-265870@lists.php.net to get a copy of this message
[snip] I'm going to be inserting data from a PHP form into a mysql field. The data could contain special characters like < > ' " \ /, etc. How do I handle that? just $data = addslashes(htmlspecialchars($data)); before the insert query? because later on the data will be read back from the mysql db and I don't want it to contain a special character that would break the PHP script. [/snip] I would use http://us3.php.net/mysql_real_escape_string

« previous php.general (#265870) next »