mysql_real_escape_string

(unknown)

mysql_real_escape_string --  Escapes special characters in a string for use in a SQL statement, taking into account the current charset of the connection.

Description

string mysql_real_escape_string ( string unescaped_string [, resource link_identifier])

This function will escape special characters in the unescaped_string, taking into account the current charset of the connection so that it is safe to place it in a mysql_query().

Not: mysql_real_escape_string() does not escape % and _.

Örnek 1. mysql_real_escape_string() example

<?php
$link = mysql_connect('localhost', 'myname', 'secret');
$item = "Zak's and Derick's Laptop";
$escaped_item = mysql_real_escape_string($item);
printf ("Escaped string: %s\n", $escaped_item);
?>

The above example would produce the following output:
Escaped string: Zak\'s and Derick\'s Laptop

See also: mysql_escape_string() mysql_character_set_name()