Jump to content

mysql_real_escape_string() / MYSQL question


fubowl

Recommended Posts

Hey all.

 

mysql_real_escape_string() seems to be working fine for me, but I'm wondering why the entries in the database don't reflect my SQL query.

 

For example, here is the string php is sending to MYSQL:

insert into bands (bandname, hometown, website, creation, bio, addedon) values ('band', '\'gaewg\"f gswogsw<?php  OR \'\'=\' rswaiohgri ', '', '1992', '\' OR \'\'=\'', '10182010')

 

This has already been run through mysql_real_escape_string(), but when I go to phpmyadmin here is what I see:

`bands` (`id`, `bandname`, `creation`, `photo`, `bio`, `hometown`, `website`, `addedon`) VALUES
(34, 'band', '1992', '', ''' OR ''''=''', '''gaewg"f gswogsw<?php  OR ''''='' rswaiohgri ', '', '10182010');

 

My question is does it matter if it's not slashed in the database? Might be just a newbie here but isn't that how injection works? Anyhow, just let me know wise phpfreaks users. Thanks in advance.

Link to comment
Share on other sites

That's how it should be. Slashes are needed for MySQL to know it has to treat the following character as a regular character, not a sepcial one. Once data is in database, there's no point in having slashes with it.

Link to comment
Share on other sites

This thread is more than a year old. Please don't revive it unless you have something important to add.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.