mysql_real_escape_string() 01-17-2014, 06:26 AM
#1
how can a hacker bypass query filters like addslashes() and mysql_real_escape_string() in a POST parameter?
thanks. I'v searched in google to use multibyte character encoding but it seems slashes are still added to the query.
are those filters good enough to protect my site?
thanks. I'v searched in google to use multibyte character encoding but it seems slashes are still added to the query.
are those filters good enough to protect my site?