dongyue5686 2010-10-20 22:56
浏览 36
已采纳

从PHP框架中转义MySQL中的字符

I was wondering if when using the database library in Codeigniter there was a way to automatically escape all the inputs to prevent injection. I know I can use mysql_real_escape_string() to do it, but I wondered it this was already setup to do this automatically, if not are there any frameworks that have this included?

Thanks!

  • 写回答

3条回答 默认 最新

  • duanna1407 2010-10-20 23:23
    关注

    In order to use prepared statements, you can simply use query bindings with CodeIgniter.

    $query = 'SELECT id, name FROM user WHERE name = ?';
    $bind = array('Jake');
    $this->db->query($query, $bind);
    

    More info found here.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论
查看更多回答(2条)

报告相同问题?