dousi8559 2009-08-29 01:52
浏览 43
已采纳

PHP和MySQL输入字符串转义问题

I've a weird string escape problem with my PHP script. I'm trying to get data from iSnare and put them into MySQL table.

I'm reading POST data and escaping strings with mysql_real_espace_string() function, also I can insert same data to .txt file without a problem but when I try to insert data into table, it cuts the string from apostrophes (') (or another char sometimes)

If that helps, my tables and fields are UTF8 and utf8_general_ci..

include("database.php");

 function security_sql($x){
    return mysql_real_escape_string(trim(stripslashes($x)));
 }

$title = security_sql($_POST["article_title"]);
$first_name = security_sql($_POST["article_author"]);
$description = security_sql($_POST["article_summary"]);
$category = security_sql($_POST["article_category"]);
$article = security_sql($_POST["article_body_text"]);
$article_html = security_sql($_POST["article_body_html"]);
$resource_box = security_sql($_POST["article_bio_text"]);
$resource_box_html = security_sql($_POST["article_bio_html"]);
$keywords = security_sql($_POST["article_keywords"]);
$email = security_sql($_POST["article_email"]);


// Writes fine to text file
$fp = fopen('test.txt', 'a');
fwrite($fp, $title."
");
fwrite($fp, $article."



");
fclose($fp);



// BUT DOESNT WORK FINE WITH MYSQL
mysql_query("INSERT INTO articles (first_name, email, title, description, article, article_html, category, resource_box, resource_box_html, keywords, distributor, distributor_host) values (
                                                 '".$first_name."',
                                                 '".$email."',
                                                 '".$title."',
                                                 '".$description."',
                                                 '".$article."',
                                                 '".$article_html."',
                                                 '".$category."',
                                                 '".$resource_box."',
                                                 '".$resource_box_html."',
                                                 '".$keywords."',
                                                 'isnare',
                                                 '".$_SERVER['REMOTE_ADDR']."'
                                                 )") or die(mysql_error());
  • 写回答

1条回答 默认 最新

  • duangenshi9836 2009-08-29 02:04
    关注

    I'd reccomend using htmlentities with the ENT_QUOTES flag as a part of your own sanitizing function.

    function clean($string) {
        $ret = str_replace('=','=',$string);
        $ret = htmlentities($ret,ENT_QUOTES);
        return $ret;
        }
    

    Above is the very simple sanitizing function I use for content output to a web browser stored in a relational database. It's probably not perfect, but it works well for me. (Note, = must be replaced to prevent injected queries involving integers)

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥20 求快手直播间榜单匿名采集ID用户名简单能学会的
  • ¥15 DS18B20内部ADC模数转换器
  • ¥15 做个有关计算的小程序
  • ¥15 MPI读取tif文件无法正常给各进程分配路径
  • ¥15 如何用MATLAB实现以下三个公式(有相互嵌套)
  • ¥30 关于#算法#的问题:运用EViews第九版本进行一系列计量经济学的时间数列数据回归分析预测问题 求各位帮我解答一下
  • ¥15 setInterval 页面闪烁,怎么解决
  • ¥15 如何让企业微信机器人实现消息汇总整合
  • ¥50 关于#ui#的问题:做yolov8的ui界面出现的问题
  • ¥15 如何用Python爬取各高校教师公开的教育和工作经历