doudu5029 2013-06-15 23:04
浏览 82
已采纳

php上的自动字符串转义

I'm building a neat website for my friend, and I noticed that the site escaped the input from textboxes, textareas, etc. automatically.

Does this mean that I don't have to add mysql_real_escape_string when I want to insert the data in my mysql database and I can just leave it as it is?

Or is this a potential security risk?

  • 写回答

2条回答 默认 最新

  • dsa456369 2013-06-15 23:54
    关注

    It does not really matter where the escaping took place, be it, when the form was being posted, or when the actual query to database was being made. mysql_* functions is in the process of being deprecated, and should no longer be in operation.

    If you want neat, secure website. Learn to use either the mysql_i (i is for "improved") or better yet, the database agnostic interface called PDO interface. Both, will give you the neatness you need, and additional security boost.

    You can get a tutorial for PDO here

    and for Mysqli here

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论
查看更多回答(1条)

报告相同问题?

悬赏问题

  • ¥15 使用ue5插件narrative时如何切换关卡也保存叙事任务记录
  • ¥20 软件测试决策法疑问求解答
  • ¥15 win11 23H2删除推荐的项目,支持注册表等
  • ¥15 matlab 用yalmip搭建模型,cplex求解,线性化处理的方法
  • ¥15 qt6.6.3 基于百度云的语音识别 不会改
  • ¥15 关于#目标检测#的问题:大概就是类似后台自动检测某下架商品的库存,在他监测到该商品上架并且可以购买的瞬间点击立即购买下单
  • ¥15 神经网络怎么把隐含层变量融合到损失函数中?
  • ¥15 lingo18勾选global solver求解使用的算法
  • ¥15 全部备份安卓app数据包括密码,可以复制到另一手机上运行
  • ¥20 测距传感器数据手册i2c