note 37565 deleted from security.database by aidan
| From: | aidan@php.net | Date: | Tue, 07 Sep 2004 23:00:46 +0000 |
| Subject: | note 37565 deleted from security.database by aidan | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-76177@lists.php.net to get a copy of this message | ||
Note Submitter:
----
i use the following functions for all variables inside mysql queries:
<?php
function sqlstr($s)
{
return "'" . mysql_escape_string($s) . "'";
}
// example query:
mysql_query("SELECT * FROM users WHERE username=" . sqlstr($_REQUEST['name']) .
" AND password=" . sqlstr($_REQUEST['password']));
?>
note that you can use sqlstr() for integer fields, too.
mysql accepts SELECT * FROM table WHERE intfield='2'