Decoding mysql_real_escape_string() for outputting HTML

前端 未结 9 2326
萌比男神i
萌比男神i 2020-12-16 16:50

I\'m trying to protect myself from sql injection and am using:

mysql_real_escape_string($string);

When posting HTML it looks something like

9条回答
  •  余生分开走
    2020-12-16 17:30

    use the following function to remove slashes while showing on HTML page:

    stripslashes();

    eg. $html=stripslashes($html); OR $html=stripslashes($row["fieldname"]);

提交回复
热议问题