Complete PHP MySQL Reference
The mysql_real_escape_string() function escapes special characters in a string for use in an SQL statement
The following characters are affected:
This function returns the escaped string on success, or FALSE on failure.
| Parameter | Description |
|---|---|
| string | Required. Specifies the string to be escaped |
| connection | Optional. Specifies the MySQL connection. If not specified, the last connection opened by mysql_connect() or mysql_pconnect() is used. |
Note: Use this function to prevent database attack!
Database attack. This example demonstrates what could happen if we do not use the mysql_real_escape_string() function on the username and password:
The SQL sent would be:
This means that anyone could log in without a valid password!
The correct way to do it to prevent database attack:
Complete PHP MySQL Reference
The perfect solution for professionals who need to balance work, family, and career building.
More than 10 000 certificates already issued!
The HTML Certificate documents your knowledge of HTML.
The HTML5 Certificate documents your knowledge of advanced HTML5.
The CSS Certificate documents your knowledge of advanced CSS.
The JavaScript Certificate documents your knowledge of JavaScript and HTML DOM.
The jQuery Certificate documents your knowledge of jQuery.
The XML Certificate documents your knowledge of XML, XML DOM and XSLT.
The ASP Certificate documents your knowledge of ASP, SQL, and ADO.
The PHP Certificate documents your knowledge of PHP and SQL (MySQL).
Your message has been sent to W3Schools.