Re: is it safe to stripslashes() on all form variables?

From: Date: Tue, 17 Apr 2001 00:24:39 +0000
Subject: Re: is it safe to stripslashes() on all form variables?
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-48854@lists.php.net to get a copy of this message
So sprach Noah Spitzer-Williams am Mon, Apr 16, 2001 at 12:45:43PM -0400: > would there be any problems caused if i used the stripslashes() function on > all posted variables from a form to eliminate sql query errors? Uhm, why stripslashes() the values? Wouldn't it be better to addslashes() the value, and then when retrieving the values from the database to stripslashes() the value? With addslashes(), you'd be sure that everything is properly escaped. BTW: Where's the difference between addslashes() and the undocumented function mysql_escape_string()? ( see http://php.net/ChangeLog-4.php#4.0.3 ) Alexander Skwar -- How to quote: http://learn.to/quote (german) http://quote.6x.to (english) Homepage: http://www.digitalprojects.com | http://www.iso-top.de iso-top.de - Die günstige Art an Linux Distributionen zu kommen Uptime: 2 hours 13 minutes

« previous php.general (#48854) next »