note 20013 deleted from function.addslashes by betz
| From: | betz@php.net | Date: | Mon, 26 Sep 2005 22:04:35 +0000 |
| Subject: | note 20013 deleted from function.addslashes by betz | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-95819@lists.php.net to get a copy of this message | ||
Note Submitter: phpman at priorwebsites.com
----
You MySQL folks might also want to check out mysql_escape_string().
--------- copied from mysql_escape_string():
If you're wondering what's the difference between mysql_escape_string() and
AddSlashes(), I found this from looking at the source code of MySQL
3.23.32 and PHP 4.0.6:
- mysql_escape_string calls MySQL's library function of the same name,
which prepends slashes to the following characters: NUL (\x00), \n, \r, \,
', " and \x1a.
- AddSlashes escapes NUL, ', " and \.
While mysql_escape_string seems safer, my experience shows that escaping
strings with AddSlashes (which is also done automatically if
magic_quotes_gpc is on) is sufficient, so it seems you can pick whichever
you wish.