note 30844 added to function.mysql-escape-string
| From: | p2pwrox at ndc dot co dot za | Date: | Tue, 01 Apr 2003 07:06:34 +0000 |
| Subject: | note 30844 added to function.mysql-escape-string | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-46048@lists.php.net to get a copy of this message | ||
Have any of you bothered to read the MySQL manual?
mysql_escape_string() is used to "create a legal SQL string that you can use in a SQL
statement". It's primary use is to allow binary BLOB data to co-exist within an ASCII SQL
statement without confusing the SQL parser. For this reason tokens such as " and ' are
escaped so the parser doesn't think you're ending the blob string prematurely. NUL is
escaped because mysql is written in C and uses C strings which use NUL as a terminator. Similar
explanations apply for the other escaped chars.
Protecting an SQL string from abuse is NOT the primary reason for this function. It's just a
bonus!
--
http://www.php.net/manual/en/function.mysql-escape-string.php
http://master.php.net/manage/user-notes.php?action=edit+30844
http://master.php.net/manage/user-notes.php?action=delete+30844
http://master.php.net/manage/user-notes.php?action=reject+30844