Why cannot this method prevent SQL injection? First of all, I don't know if MySQL can add single quotation marks for all types of data. I just tried to add single quotation marks around the integer.
If it is true that all types of data can be enclosed in single quotes, a single quotation mark will be added to any data when a MySQL statement is generated, use mysql_escape_string to escape all special characters in the received characters. In this way, the received string is completely "restricted" between single quotes.
However, it seems that the conversion and normal strings in strings similar to the like clause are different once and for all. In addition, if any update in the AMP involves escaping, problems may occur. Are there solutions to these two problems once and for all? Is there any other problem?
Reply to discussion (solution)
The conversion and normal strings in the strings after the like clause seem to be different.
Why?
Both MySQL and pdo provide data binding.
Manual escape is not required when data binding is used.
The conversion and normal strings in the strings after the like clause seem to be different.
Why?
Both MySQL and pdo provide data binding.
Manual escape is not required when data binding is used.
The backslash in like seems to be \\\.
Don't come up with an instance.
Don't come up with an instance.
It seems that it is related to PHP and cannot be interviewed directly in the command line. It is completely normal in the command line. In addition, three backslashes are required in phpmyadmin.
Don't come up with an instance.
It seems that it is related to PHP and cannot be interviewed directly in the command line. It is completely normal in the command line. In addition, three backslashes are required in phpmyadmin.
I just typed the backslash into a diagonal line, and I can try it out in the command line.
mysql> use testDatabase changedmysql> create table backlash (id int, value char(20));Query OK, 0 rows affected (0.00 sec)mysql> insert into backlash(id, value) values(1,'\\');Query OK, 1 row affected (0.00 sec)mysql> select * from backlash where value='\\';+------+-------+| id | value |+------+-------+| 1 | \ |+------+-------+1 row in set (0.00 sec)mysql> select * from backlash where value like '%\\%';Empty set (0.00 sec)mysql> select * from backlash where value like '%\\\%';+------+-------+| id | value |+------+-------+| 1 | \ |+------+-------+1 row in set (0.00 sec)mysql>
Don't come up with an instance.
To use PHP, add six backslashes:
';$result=mysql_query($sql, $conn);$row=mysql_fetch_row($result);echo $row[0];echo '
';?>
In my previous work, I only obtained the backslash through get, so we can simply use three. Confused.