note 36634 deleted from function.mysql-real-escape-string by nlopess

From: Date: Tue, 09 Mar 2004 14:54:49 +0000
Subject: note 36634 deleted from function.mysql-real-escape-string by nlopess
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-66494@lists.php.net to get a copy of this message
Note Submitter: Procyon [NoSpAm] [AT] gmx [DOT] de ---- Perhaps you don't know whether the data you get comes from a gpc variable and is already escaped (magic_quotes_gpc=On) or from a local function and needs to be escaped (magic_quotes_runtime=Off) before it is passed into a mysql_query. This is the solution I thought of: remove all possibly escaped characters from the string and then escape what is left over. This is my code: <?php function safesql($string) { settype($string,"string"); while($string!=stripslashes($string) $string=stripslashes($string); return(addslashes($string)); } ?> Unfortunately, the signs (un)escaped by stripslashes/addslashes are not the only ones mysql uses to seperate names/values etc. So it would be better to know which characters mysql_real_escape_string() and mysql_escape_string() touches ;) (` is one, for example). Then we could write a "really safe" function for escaping special mysql characters ... I think this is a good start: <?php function safesql($string) { settype($string,"string"); $string=str_replace("`","",$string); while($string!=stripslashes($string) $string=stripslashes($string); return(mysql_real_escape_string($string)); } ?>

« previous php.notes (#66494) next »