note 36634 deleted from function.mysql-real-escape-string by nlopess
| From: | nlopess@php.net | Date: | Tue, 09 Mar 2004 14:54:49 +0000 |
| Subject: | note 36634 deleted from function.mysql-real-escape-string by nlopess | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-66494@lists.php.net to get a copy of this message | ||
Note Submitter: Procyon [NoSpAm] [AT] gmx [DOT] de
----
Perhaps you don't know whether the data you get comes from a gpc variable and is already
escaped (magic_quotes_gpc=On) or from a local function and needs to be escaped
(magic_quotes_runtime=Off) before it is passed into a mysql_query. This is the solution I thought
of: remove all possibly escaped characters from the string and then escape what is left over. This
is my code:
<?php
function safesql($string)
{
settype($string,"string");
while($string!=stripslashes($string)
$string=stripslashes($string);
return(addslashes($string));
}
?>
Unfortunately, the signs (un)escaped by stripslashes/addslashes are not the only ones mysql uses to
seperate names/values etc. So it would be better to know which characters mysql_real_escape_string()
and mysql_escape_string() touches ;) (` is one, for example). Then we could write a "really
safe" function for escaping special mysql characters ...
I think this is a good start:
<?php
function safesql($string)
{
settype($string,"string");
$string=str_replace("`","",$string);
while($string!=stripslashes($string)
$string=stripslashes($string);
return(mysql_real_escape_string($string));
}
?>