Jump to content

Mysql and quotes


TheFilmGod

Recommended Posts

In one of my tables in mysql  I will have a name field.

 

Some names can be O'Brien and thus they have a quote. So during my validation step I will allow names to contain single quotes.

 

Can anyone please explain the extra precautions I may have to take to ensure that the inputed names don't inject into mysql and maliciously corrupt the system?

Link to comment
https://forums.phpfreaks.com/topic/111415-mysql-and-quotes/
Share on other sites

$name = mysql_real_escape_string($_GET['name']);

 

That will do everything needed to make sure dynamic user controlled input cant screw your query up

 

Isn't this deprecated? Or am I getting confused with some other mysql quote function?

 

And what exactly does the function do?

Link to comment
https://forums.phpfreaks.com/topic/111415-mysql-and-quotes/#findComment-571960
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.