note 30844 deleted from function.mysql-escape-string by aidan

From: Date: Wed, 11 Aug 2004 14:07:53 +0000
Subject: note 30844 deleted from function.mysql-escape-string by aidan
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-74449@lists.php.net to get a copy of this message
Note Submitter: p2pwrox@ndc.co.za ---- Have any of you bothered to read the MySQL manual? mysql_escape_string() is used to "create a legal SQL string that you can use in a SQL statement". It's primary use is to allow binary BLOB data to co-exist within an ASCII SQL statement without confusing the SQL parser. For this reason tokens such as " and ' are escaped so the parser doesn't think you're ending the blob string prematurely. NUL is escaped because mysql is written in C and uses C strings which use NUL as a terminator. Similar explanations apply for the other escaped chars. Protecting an SQL string from abuse is NOT the primary reason for this function. It's just a bonus!

« previous php.notes (#74449) next »