You are here: Re: Trouble escaping / Misc nightmare « PHP Programming Language « IT news, forums, messages
Re: Trouble escaping / Misc nightmare

Posted by Malcolm Dew-Jones on 06/29/05 02:01

Ken Robinson (kenrbnsn@rbnsn.com) wrote:


: Malcolm Dew-Jones wrote:
: > $id = mysql_escape_string($_REQUEST[id]);
: >
: > $sql = "select * from the_table where ID='$id'";
: >
: >
: > Always escape your values before stuffing them into the sql string, (not
: > just when you think you might need it).

: You can also use urlencode($var) or htmlentities($var,ENT_QUOTES)
: before inserting $var into your database.

You can, but you should still use mysql_escape_string on the result when
you embed it in an sql query being handled by mysql.


--

This space not for rent.

 

Navigation:

[Reply to this message]


Удаленная работа для программистов  •  Как заработать на Google AdSense  •  England, UK  •  статьи на английском  •  PHP MySQL CMS Apache Oscommerce  •  Online Business Knowledge Base  •  DVD MP3 AVI MP4 players codecs conversion help
Home  •  Search  •  Site Map  •  Set as Homepage  •  Add to Favourites

Copyright © 2005-2006 Powered by Custom PHP Programming

Сайт изготовлен в Студии Валентина Петручека
изготовление и поддержка веб-сайтов, разработка программного обеспечения, поисковая оптимизация