Best way to escape strings for sql inserts?

心不动则不痛 提交于 2019-12-07 05:42:29

问题


What is the best way to escape strings for sql inserts, updates?

I want to allow special characters including ' and ". Is the best way to search and replace each string before I use it in an insert statement?

Thanks

Duplicate of: Best way to defend against mysql injection and cross site scripting


回答1:


You should be using parameterized queries (so by extension, a DB interface library that supports parameterized queries) so that SQL injection can't happen.




回答2:


If you're talking about data values for your fields, then the best way is to use mysql_real_escape_string(). (Some people like mysqli; can't say I do.) If you're talking about allowing user-submitted queries... well, let's hope you're not talking about that.



来源:https://stackoverflow.com/questions/633109/best-way-to-escape-strings-for-sql-inserts

易学教程内所有资源均来自网络或用户发布的内容,如有违反法律规定的内容欢迎反馈
该文章没有解决你所遇到的问题?点击提问,说说你的问题,让更多的人一起探讨吧!