Re: regex and mysql - looking for opinions.
| From: | Christian Reiniger | Date: | Thu, 19 Apr 2001 09:32:09 +0000 |
| Subject: | Re: regex and mysql - looking for opinions. | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-49340@lists.php.net to get a copy of this message | ||
On Wednesday 18 April 2001 22:03, you wrote:
> and do various searches etc. I was curious as to what most people find
> the best way keep thier mysql queries from getting messed up by user
> entered data. None of my searches or database data has or needs any
Simply using addslashes () or the magic_quotes_gpc setting will do fine
for strings.
For numbers just cast them to int before inserting 'em in the query:
$MyNum = (int) $MyNum;
$Query = "INSERT INTO foo (intval) VALUES ($MyNum)';
--
Christian Reiniger
LGDC Webmaster (http://sunsite.dk/lgdc/)
/* you are not expected to understand this */
- from the UNIX V6 kernel source