Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.lang.php > #2242
| Message-Id | <4727679.ypaU67uLZW@PointedEars.de> |
|---|---|
| From | Thomas 'PointedEars' Lahn <PointedEars@web.de> |
| Organization | PointedEars Software (PES) |
| Date | 2011-06-18 08:35 +0200 |
| Subject | Re: Form fields to database and back? |
| Newsgroups | comp.lang.php |
| References | <j48lv6prpshk57ora2dsp6b2lvp16vkvtu@4ax.com> <ite935$1b5$1@dont-email.me> <plelv6lp4m78uv2tg5mjtm9bd5f13douk5@4ax.com> <1655216.aK4W3vaeNJ@PointedEars.de> <sppnv6tecikiudrbhkq4v4rcacioqihvnu@4ax.com> |
| Followup-To | comp.lang.php |
Followups directed to: comp.lang.php
bobmct wrote: > From field to database I used mysql_real_escape_string. > > When I look at the actual data stored in the db field that function > inserted backslashes before each double quote. > > To display the retrieved db field I ran it through htmlspecialchars() > but the backslashes still remained. I had to use stripslashes to > remove them. Then you are doing something wrong. mysql_real_escape_string() – AISB, prepared statements (PS) with MySQLi or PDO are preferable to that – only escapes the data for the query, so that SQL code injection is prevented. It does _not_ change the data to be stored. So when you retrieve the data you should not need to unescape anything. Perhaps you have used mysql_real_escape_string() on the retrieved data also, but that is _not_ its purpose. > Works for now. By chance. mysql_real_escape_string() does more than addslashes(), which is why it is preferable to that. (And PS are preferable to it because they consider the type automatically, among other advantages.) PointedEars -- Use any version of Microsoft Frontpage to create your site. (This won't prevent people from viewing your source, but no one will want to steal it.) -- from <http://www.vortex-webdesign.com/help/hidesource.htm> (404-comp.)
Back to comp.lang.php | Previous | Next — Previous in thread | Find similar | Unroll thread
Form fields to database and back? bobmct <bobm3@worthless.info> - 2011-06-16 20:36 -0400
Re: Form fields to database and back? The Natural Philosopher <tnp@invalid.invalid> - 2011-06-17 01:43 +0100
Re: Form fields to database and back? Jerry Stuckle <jstucklex@attglobal.net> - 2011-06-16 21:03 -0400
Re: Form fields to database and back? Jerry Stuckle <jstucklex@attglobal.net> - 2011-06-16 21:02 -0400
Re: Form fields to database and back? bobmct <bobm3@worthless.info> - 2011-06-16 22:34 -0400
Re: Form fields to database and back? Jerry Stuckle <jstucklex@attglobal.net> - 2011-06-16 23:50 -0400
Re: Form fields to database and back? bobmct <bobm3@worthless.info> - 2011-06-17 07:09 -0400
Re: Form fields to database and back? bobm3@worthless.info - 2011-06-17 15:18 +0000
Re: Form fields to database and back? Jerry Stuckle <jstucklex@attglobal.net> - 2011-06-17 16:44 -0400
Re: Form fields to database and back? "Álvaro G. Vicario" <alvaro.NOSPAMTHANX@demogracia.com.invalid> - 2011-06-17 13:28 +0200
Re: Form fields to database and back? Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2011-06-17 22:03 +0200
Re: Form fields to database and back? bobmct <bobm3@worthless.info> - 2011-06-17 19:52 -0400
Re: Form fields to database and back? Jerry Stuckle <jstucklex@attglobal.net> - 2011-06-17 21:01 -0400
Re: Form fields to database and back? Captain Paralytic <paul_lautman@yahoo.com> - 2011-06-22 09:05 -0700
Re: Form fields to database and back? Jerry Stuckle <jstucklex@attglobal.net> - 2011-06-22 13:15 -0400
Re: Form fields to database and back? Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2011-06-18 08:35 +0200
csiph-web