What is the best way to escape strings for sql inserts, updates?
I want to allow special characters including ' and ". Is the best way to search and replace each string before I use it in an insert statement?
Thanks
Duplicate of: Best way to defend against mysql injection and cross site scripting
You should be using parameterized queries (so by extension, a DB interface library that supports parameterized queries) so that SQL injection can't happen.
If you love us? You can donate to us via Paypal or buy me a coffee so we can maintain and grow! Thank you!
Donate Us With