Re: is it safe to stripslashes() on all form variables?
| From: | Alexander Skwar | Date: | Tue, 17 Apr 2001 00:24:39 +0000 |
| Subject: | Re: is it safe to stripslashes() on all form variables? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-48854@lists.php.net to get a copy of this message | ||
So sprach Noah Spitzer-Williams am Mon, Apr 16, 2001 at 12:45:43PM -0400:
> would there be any problems caused if i used the stripslashes() function on
> all posted variables from a form to eliminate sql query errors?
Uhm, why stripslashes() the values? Wouldn't it be better to addslashes()
the value, and then when retrieving the values from the database to
stripslashes() the value?
With addslashes(), you'd be sure that everything is properly escaped.
BTW: Where's the difference between addslashes() and the undocumented
function mysql_escape_string()? ( see http://php.net/ChangeLog-4.php#4.0.3 )
Alexander Skwar
--
How to quote: http://learn.to/quote (german) http://quote.6x.to (english)
Homepage: http://www.digitalprojects.com | http://www.iso-top.de
iso-top.de - Die günstige Art an Linux Distributionen zu kommen
Uptime: 2 hours 13 minutes