note 56792 added to function.mysql-real-escape-string
| From: | Sanadosmuhadib-at-eof dot at at osu1 dot php dot net | Date: | Thu, 15 Sep 2005 12:27:52 +0000 |
| Subject: | note 56792 added to function.mysql-real-escape-string | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-95215@lists.php.net to get a copy of this message | ||
in times of mysql injection ...
this function helps me to watch the arguments for sql statements.
problem was that different user send chars and htmlspecialchars in different charsets, this is
compensated and converted back to iso-8859-1 then the string gets escaped.
you still have to stripslashes if you server is running with magic_quotes.
function mysql_save ($string) {
if(is_numeric($string))
$argument = $string;
else
$argument = "'".
mysql_real_escape_string(
html_entity_decode(
htmlspecialchars(
$string),ENT_NOQUOTES,"ISO-8859-1"))
."'";
return $argument;
}
----
Manual Page -- http://www.php.net/manual/en/function.mysql-real-escape-string.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+56792
Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+56792&report=yes&reason=added+to+the+manual
Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+56792&report=yes&reason=bad+code
Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+56792&report=yes&reason=spam
Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+56792&report=yes&reason=useless
Delete: non-english -- http://master.php.net/manage/user-notes.php?action=delete+56792&report=yes&reason=non-english
Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+56792&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+56792&report=yes
Search -- http://master.php.net/manage/user-notes.php