Htmlentities vs addslashes vs mysqli_real_escape_string

前端 未结 7 1102
悲哀的现实
悲哀的现实 2020-12-18 03:04

I\'ve been doing some reading on securing PHP applications, and it seems to me that mysqli_real_escape_string is the correct function to use when inserting data

7条回答
  •  慢半拍i
    慢半拍i (楼主)
    2020-12-18 03:51

    You could also use the PDO libs which does most of the escaping for you, in case you may use PHP5 on the servers.

    On echoing back I'd personally prefer htmlspecialchars, but one might correct me

提交回复
热议问题