note 77388 modified in function.mysql-real-escape-string by danbrown
| From: | danbrown@php.net | Date: | Sat, 14 Mar 2009 15:05:21 +0000 |
| Subject: | note 77388 modified in function.mysql-real-escape-string by danbrown | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-151921@lists.php.net to get a copy of this message | ||
if you're doing a mysql wildcard query with
LIKE, GRANT, or REVOKE
you may use addcslashes to escape the string:
<?php
$param = mysql_real_escape_string($param);
$param = addcslashes($param, '%_');
?>
--was--
if you're doing a mysql wildcard query with
LIKE, GRANT, or REVOKE
you may use addcslashes to escape the string:
<?
$param = mysql_real_escape_string($param);
$param = addcslashes($param, '%_');
?>
http://php.net/manual/en/function.mysql-real-escape-string.php