SQL Escape Characters in PHP
| From: | Keith Devens | Date: | Tue, 01 Aug 2000 19:24:16 +0000 |
| Subject: | SQL Escape Characters in PHP | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-9527@lists.php.net to get a copy of this message | ||
Hi, quick question. When you send an sql statement to a database (through
ODBC, etc.) if a string that you send has single quotes in it they have to
be escaped. JDBC has a thing where you can automatically have it escape the
string for you, for instance:
java.sql.PreparedStatement pstmt = connection.prepareStatement("insert into
clients (client_name, client_address) values(?, ?)");
pstmt.setString(1, "St. Joseph's Hospital");
pstmt.setString(2, "1 Good Samaritan Rd.");
pstmt.executeUpdate();
You don't even have to put single quotes around the question marks in the
prepared statement string because it knows what to do.
Is there anything equivalent in PHP, or do I have to do ereg_replaces on
every string I send to the database to make sure I don't break it with
unescaped quote characters?
Thanks!
Keith