I understand MSSQL uses the ' character to escape - however, the only functions I see built for escaping strings that are going into MSSQL dBs is:


function mssql_escape($str) {
    return str_replace("'", "''", $str);


What about double quotes? Do they need escaped? Do asterisks or anything else need escaped?



