dppcyt6157 2016-07-26 10:25
浏览 8
已采纳

MySQL插入不受信任的数据[重复]

This question already has an answer here:

I see a lot of post about inserting into MySQL database. The vast amount of them seem to forget that its user input we are dealing with. What would be the best was to insert data in to the table. Would mysqli_real_escape_string be okay? Or would using prepared statements be a better option, maybe both?

</div>
  • 写回答

1条回答 默认 最新

  • dongyishe6689 2016-07-26 10:27
    关注

    mysqli_real_escape_string is good, but not always safe as prepared statement.

    mysql_real_escape_string() prone to the same kind of issues affecting addslashes().

    So use of prepared statement is much better.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 linux驱动,linux应用,多线程
  • ¥20 我要一个分身加定位两个功能的安卓app
  • ¥15 基于FOC驱动器,如何实现卡丁车下坡无阻力的遛坡的效果
  • ¥15 IAR程序莫名变量多重定义
  • ¥15 (标签-UDP|关键词-client)
  • ¥15 关于库卡officelite无法与虚拟机通讯的问题
  • ¥15 目标检测项目无法读取视频
  • ¥15 GEO datasets中基因芯片数据仅仅提供了normalized signal如何进行差异分析
  • ¥100 求采集电商背景音乐的方法
  • ¥15 数学建模竞赛求指导帮助