note 30844 added to function.mysql-escape-string

From: Date: Tue, 01 Apr 2003 07:06:34 +0000
Subject: note 30844 added to function.mysql-escape-string
Groups: php.notes 
Request: Send a blank email to php-notes+get-46048@lists.php.net to get a copy of this message
Have any of you bothered to read the MySQL manual? mysql_escape_string() is used to "create a legal SQL string that you can use in a SQL statement". It's primary use is to allow binary BLOB data to co-exist within an ASCII SQL statement without confusing the SQL parser. For this reason tokens such as " and ' are escaped so the parser doesn't think you're ending the blob string prematurely. NUL is escaped because mysql is written in C and uses C strings which use NUL as a terminator. Similar explanations apply for the other escaped chars. Protecting an SQL string from abuse is NOT the primary reason for this function. It's just a bonus! -- http://www.php.net/manual/en/function.mysql-escape-string.php http://master.php.net/manage/user-notes.php?action=edit+30844 http://master.php.net/manage/user-notes.php?action=delete+30844 http://master.php.net/manage/user-notes.php?action=reject+30844

« previous php.notes (#46048) next »