note 16284 deleted from function.mysql-escape-string by aidan
| From: | aidan@php.net | Date: | Wed, 11 Aug 2004 14:08:33 +0000 |
| Subject: | note 16284 deleted from function.mysql-escape-string by aidan | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-74457@lists.php.net to get a copy of this message | ||
Note Submitter: mitja at doticni dot net
----
If you're wondering what's the difference between mysql_escape_string() and AddSlashes(),
I found this from looking at the source code of MySQL 3.23.32 and PHP 4.0.6:
- mysql_escape_string calls MySQL's library function of the same name, which prepends slashes
to the following characters: NUL (\x00), \n, \r, \, ', " and \x1a.
- AddSlashes escapes NUL, ', " and \.
While mysql_escape_string seems safer, my experience shows that escaping strings with AddSlashes
(which is also done automatically if magic_quotes_gpc is on) is sufficient, so it seems you can pick
whichever you wish.