note 59134 deleted from function.addslashes by nlopess
| From: | nlopess@php.net | Date: | Fri, 31 Mar 2006 16:19:30 +0000 |
| Subject: | note 59134 deleted from function.addslashes by nlopess | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-107086@lists.php.net to get a copy of this message | ||
Note Submitter: ronald
----
'safed' claims that addslashes() is no good for securing MySQL queries, as it does not
escape \n and \r. However the MySQL reference
(http://dev.mysql.com/doc/refman/4.1/en/mysql-real-escape-string.html) states "Strictly
speaking, MySQL requires only that backslash and the quote character used to quote the string in the
query be escaped. This function quotes the other characters to make them easier to read in log
files."
So addslashes() should be fine from that point of view.