Re: SQL Escape Characters in PHP
| From: | Chris Murley | Date: | Tue, 01 Aug 2000 19:25:52 +0000 |
| Subject: | Re: SQL Escape Characters in PHP | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-9529@lists.php.net to get a copy of this message | ||
LOL, as i was just taught, the function addslashes works ;-)
On Tue, 1 Aug 2000, Keith Devens wrote:
> Hi, quick question. When you send an sql statement to a database (through
> ODBC, etc.) if a string that you send has single quotes in it they have to
> be escaped. JDBC has a thing where you can automatically have it escape the
> string for you, for instance:
>
> java.sql.PreparedStatement pstmt = connection.prepareStatement("insert into
> clients (client_name, client_address) values(?, ?)");
>
> pstmt.setString(1, "St. Joseph's Hospital");
> pstmt.setString(2, "1 Good Samaritan Rd.");
> pstmt.executeUpdate();
>
> You don't even have to put single quotes around the question marks in the
> prepared statement string because it knows what to do.
>
> Is there anything equivalent in PHP, or do I have to do ereg_replaces on
> every string I send to the database to make sure I don't break it with
> unescaped quote characters?
>
> Thanks!
>
> Keith
>
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>