note 56792 deleted from function.mysql-real-escape-string by aidan

From: Date: Sat, 04 Feb 2006 12:06:20 +0000
Subject: note 56792 deleted from function.mysql-real-escape-string by aidan
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-102983@lists.php.net to get a copy of this message
Note Submitter: Sanados muhadib-at-eof.at ---- in times of mysql injection ... this function helps me to watch the arguments for sql statements. problem was that different user send chars and htmlspecialchars in different charsets, this is compensated and converted back to iso-8859-1 then the string gets escaped. you still have to stripslashes if you server is running with magic_quotes. function mysql_save ($string) { if(is_numeric($string)) $argument = $string; else $argument = "'". mysql_real_escape_string( html_entity_decode( htmlspecialchars( $string),ENT_NOQUOTES,"ISO-8859-1")) ."'"; return $argument; }

« previous php.notes (#102983) next »