Logo Questions Linux Laravel Mysql Ubuntu Git Menu
 

Best way to escape strings for sql inserts?

What is the best way to escape strings for sql inserts, updates?

I want to allow special characters including ' and ". Is the best way to search and replace each string before I use it in an insert statement?

Thanks

Duplicate of: Best way to defend against mysql injection and cross site scripting

like image 986
pixeldev Avatar asked Mar 11 '09 02:03

pixeldev


1 Answers

You should be using parameterized queries (so by extension, a DB interface library that supports parameterized queries) so that SQL injection can't happen.

like image 138
nobody Avatar answered Oct 20 '22 18:10

nobody