Shouldn't mysql_real_escape_string() leave slashes in Database?

杀马特。学长 韩版系。学妹 提交于 2019-12-01 20:17:13

You're missing it - escaping with backslashes is meant to ensure that queries aren't malformed, e.g. something like this will surely break and possibly risk SQL injections:

insert into table values ('whatever 'this' is')

and nothing will be saved in the table, whereas this:

insert into table values ('whatever \'this\' is')

will save the value "whatever 'this' is" in the table.

易学教程内所有资源均来自网络或用户发布的内容,如有违反法律规定的内容欢迎反馈
该文章没有解决你所遇到的问题?点击提问,说说你的问题,让更多的人一起探讨吧!