what does mysql_real_escape_string() really do?

后端 未结 6 817
慢半拍i
慢半拍i 2020-12-07 17:28

One thing that I hate about documentation at times (when you\'re a beginner) is how it doesn\'t really describe things in english. Would anyone mind translating this documen

6条回答
  •  刺人心
    刺人心 (楼主)
    2020-12-07 18:05

    The function adds an escape character, the backslash, \, before certain potentially dangerous characters in a string passed in to the function. The characters escaped are

    \x00, \n, \r, \, ', " and \x1a.

    This can help prevent SQL injection attacks which are often performed by using the ' character to append malicious code to an SQL query.

提交回复
热议问题