note 59134 added to function.addslashes
| From: | ronald at osu1 dot php dot net | Date: | Sun, 27 Nov 2005 11:21:55 +0000 |
| Subject: | note 59134 added to function.addslashes | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-99176@lists.php.net to get a copy of this message | ||
'safed' claims that addslashes() is no good for securing MySQL queries, as it does not
escape \n and \r. However the MySQL reference
(http://dev.mysql.com/doc/refman/4.1/en/mysql-real-escape-string.html) states "Strictly
speaking, MySQL requires only that backslash and the quote character used to quote the string in the
query be escaped. This function quotes the other characters to make them easier to read in log
files."
So addslashes() should be fine from that point of view.
----
Manual Page -- http://www.php.net/manual/en/function.addslashes.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+59134
Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+59134&report=yes&reason=added+to+the+manual
Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+59134&report=yes&reason=bad+code
Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+59134&report=yes&reason=spam
Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+59134&report=yes&reason=useless
Delete: non-english -- http://master.php.net/manage/user-notes.php?action=delete+59134&report=yes&reason=non-english
Delete: already in docs -- http://master.php.net/manage/user-notes.php?action=delete+59134&report=yes&reason=already+in+docs
Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+59134&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+59134&report=yes
Search -- http://master.php.net/manage/user-notes.php