duanlinjian5819 2012-07-18 18:32
浏览 31

转义引号php和mysql [重复]

Possible Duplicate:
Best way to prevent SQL Injection in PHP

I escape quotation marks via addslashes($str).

When i save the input from text fields to a MySQL database, is that a sufficient protection against MySQL injections or do I need to filter the input further because you can bypass this escape method? Or is there any better way to do this?

  • 写回答

5条回答 默认 最新

  • duandou8120 2012-07-18 18:34
    关注

    You should read about prepared statements in PDO: http://www.php.net/manual/en/pdo.prepared-statements.php

    评论

报告相同问题?

悬赏问题

  • ¥20 win11修改中文用户名路径
  • ¥15 win2012磁盘空间不足,c盘正常,d盘无法写入
  • ¥15 用土力学知识进行土坡稳定性分析与挡土墙设计
  • ¥70 PlayWright在Java上连接CDP关联本地Chrome启动失败,貌似是Windows端口转发问题
  • ¥15 帮我写一个c++工程
  • ¥30 Eclipse官网打不开,官网首页进不去,显示无法访问此页面,求解决方法
  • ¥15 关于smbclient 库的使用
  • ¥15 微信小程序协议怎么写
  • ¥15 c语言怎么用printf(“\b \b”)与getch()实现黑框里写入与删除?
  • ¥20 怎么用dlib库的算法识别小麦病虫害