note 59134 deleted from function.addslashes by nlopess

From: Date: Fri, 31 Mar 2006 16:19:30 +0000
Subject: note 59134 deleted from function.addslashes by nlopess
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-107086@lists.php.net to get a copy of this message
Note Submitter: ronald ---- 'safed' claims that addslashes() is no good for securing MySQL queries, as it does not escape \n and \r. However the MySQL reference (http://dev.mysql.com/doc/refman/4.1/en/mysql-real-escape-string.html) states "Strictly speaking, MySQL requires only that backslash and the quote character used to quote the string in the query be escaped. This function quotes the other characters to make them easier to read in log files." So addslashes() should be fine from that point of view.

« previous php.notes (#107086) next »