Im simply passing user data into an SQL database and collecting the data for admin view only, i am usin mysql_real_escape_string() to escape the data, I was told today that htmlentities is better to use, i have always heard the opposite. could do go a little more in depth on this with me. Also as a sid enote, if someone could provide a really good tutorial for PDO that would be wonderful
我应该使用htmlentities还是mysql_real_escape_string [关闭]
dongzhuanlei0768 2013-01-12 18:45关注The two do entirely different things. One escapes data for putting into a SQL statement (which is a bad in general: see and the other escapes data for putting into an HTML document. You're basically asking "Should I use a spoon or a fork?"
本回答被题主选为最佳回答
