note 36634 added to function.mysql-real-escape-string

From: Date: Thu, 16 Oct 2003 20:18:44 +0000
Subject: note 36634 added to function.mysql-real-escape-string
Groups: php.notes 
Request: Send a blank email to php-notes+get-58717@lists.php.net to get a copy of this message
Perhaps you don't know whether the data you get comes from a gpc variable and is already escaped (magic_quotes_gpc=On) or from a local function and needs to be escaped (magic_quotes_runtime=Off) before it is passed into a mysql_query. This is the solution I thought of: remove all possibly escaped characters from the string and then escape what is left over. This is my code: <?php function safesql($string) { settype($string,"string"); while($string!=stripslashes($string) $string=stripslashes($string); return(addslashes($string)); } ?> Unfortunately, the signs (un)escaped by stripslashes/addslashes are not the only ones mysql uses to seperate names/values etc. So it would be better to know which characters mysql_real_escape_string() and mysql_escape_string() touches ;) (` is one, for example). Then we could write a "really safe" function for escaping special mysql characters ... I think this is a good start: <?php function safesql($string) { settype($string,"string"); $string=str_replace("`","",$string); while($string!=stripslashes($string) $string=stripslashes($string); return(mysql_real_escape_string($string)); } ?> ---- Manual Page -- http://www.php.net/manual/en/function.mysql-real-escape-string.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+36634 Delete -- http://master.php.net/manage/user-notes.php?action=delete+36634&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+36634&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#58717) next »