Is mysql_real_escape_string enough to Anti SQL Injection?

后端 未结 3 1410
情书的邮戳
情书的邮戳 2020-12-03 18:32

In PHP Manual, there is a note:

Note: If this function is not used to escape data, the query is vulnerable to SQL Injection Attacks.

3条回答
  •  萌比男神i
    2020-12-03 19:18

    The best solution is PDO.

    If you're using the traditional mysql_query then running all of your data through mysql_real_escape_string() is enough.

提交回复
热议问题