參考 mysql_real_escape_string mysqli_real_escape_stringphp
mysql_real_escape_string是用來轉義字符的,主要是轉義POST或GET的參數,防治SQL注入(防注入可參考PHP防SQL注入不要再用addslashes和mysql_real_escape_string了),可是 自 PHP 5.5.0 起已廢棄,並在自 PHP 7.0.0 開始被移除html
替代的有mysqli_real_escape_string,不過mysqli_real_escape_string要求必須連接數據庫。mysql
$link = mysqli_connect("localhost", "username", "password"); /* check connection */ if (mysqli_connect_errno()) { printf("Connect failed: %s\n", mysqli_connect_error()); exit(); } $city = "'s Hertogenbosch"; $city = mysqli_real_escape_string($link, $city); echo $city;
結果:sql
\'s Hertogenbosch