note 23596 deleted from function.mysql-query by philip
| From: | philip@php.net | Date: | Wed, 06 Apr 2005 18:11:19 +0000 |
| Subject: | note 23596 deleted from function.mysql-query by philip | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-87611@lists.php.net to get a copy of this message | ||
Note Submitter: ingemar at hem dot net
----
If you shut of magic_quotes_gpc you can use this wrapper to make your mysql querys safe:
function safe_query($query, $values) {
$query_parts = preg_split("/\?/", $query);
$safe_query = array_shift($query_parts);
$needed_values = count($query_parts);
$i=0;
$ii=count($values);
for ($i=0;$i<$ii;$i++) {
$values[$i] = mysql_escape_string($values[$i]);
$safe_query .= $values[$i].array_shift($query_parts);
}
if (count($query_parts)) {
die ('Query "<i>'.$query.'</i>" needs'.
$needed_values.' values, you only sent '.$ii);
}
return mysql_query($safe_query);
}
You call this function like this:
$query = "select * from a where b='?' and c='?'";
$values = array("fo'o", "bar");
$result = safe_query($query, $values);
Mysql will then get this query:
select * from a where b='fo\'o' and c='bar'