note 56792 deleted from function.mysql-real-escape-string by aidan
| From: | aidan@php.net | Date: | Sat, 04 Feb 2006 12:06:20 +0000 |
| Subject: | note 56792 deleted from function.mysql-real-escape-string by aidan | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-102983@lists.php.net to get a copy of this message | ||
Note Submitter: Sanados muhadib-at-eof.at
----
in times of mysql injection ...
this function helps me to watch the arguments for sql statements.
problem was that different user send chars and htmlspecialchars in different charsets, this is
compensated and converted back to iso-8859-1 then the string gets escaped.
you still have to stripslashes if you server is running with magic_quotes.
function mysql_save ($string) {
if(is_numeric($string))
$argument = $string;
else
$argument = "'".
mysql_real_escape_string(
html_entity_decode(
htmlspecialchars(
$string),ENT_NOQUOTES,"ISO-8859-1"))
."'";
return $argument;
}