doudu5029 2013-06-15 23:04
浏览 82
已采纳

php上的自动字符串转义

I'm building a neat website for my friend, and I noticed that the site escaped the input from textboxes, textareas, etc. automatically.

Does this mean that I don't have to add mysql_real_escape_string when I want to insert the data in my mysql database and I can just leave it as it is?

Or is this a potential security risk?

  • 写回答

2条回答 默认 最新

  • dsa456369 2013-06-15 23:54
    关注

    It does not really matter where the escaping took place, be it, when the form was being posted, or when the actual query to database was being made. mysql_* functions is in the process of being deprecated, and should no longer be in operation.

    If you want neat, secure website. Learn to use either the mysql_i (i is for "improved") or better yet, the database agnostic interface called PDO interface. Both, will give you the neatness you need, and additional security boost.

    You can get a tutorial for PDO here

    and for Mysqli here

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论
查看更多回答(1条)

报告相同问题?

悬赏问题

  • ¥15 做个有关计算的小程序
  • ¥15 MPI读取tif文件无法正常给各进程分配路径
  • ¥15 如何用MATLAB实现以下三个公式(有相互嵌套)
  • ¥30 关于#算法#的问题:运用EViews第九版本进行一系列计量经济学的时间数列数据回归分析预测问题 求各位帮我解答一下
  • ¥15 setInterval 页面闪烁,怎么解决
  • ¥15 如何让企业微信机器人实现消息汇总整合
  • ¥50 关于#ui#的问题:做yolov8的ui界面出现的问题
  • ¥15 如何用Python爬取各高校教师公开的教育和工作经历
  • ¥15 TLE9879QXA40 电机驱动
  • ¥20 对于工程问题的非线性数学模型进行线性化