Addslashes still recommended for DB input

From: Date: Tue, 21 Aug 2007 15:26:21 +0000
Subject: Addslashes still recommended for DB input
Groups: php.internals 
Request: Send a blank email to internals+get-31791@lists.php.net to get a copy of this message
The current php.ini-recommended in CVS for 5.2 has this at line 95...
; - magic_quotes_gpc = Off         [Performance]
;     Input data is no longer escaped with slashes so that it can be sent into
;     SQL databases without further manipulation.  Instead, you should use the
;     function addslashes() on each input element you wish to send to a database.
As far as I was aware addslashes is inadequate for this purpose. Should this not point people to use database-specific escaping functions rather than addslashes? -Stut -- http://stut.net/

« previous php.internals (#31791) next »