I have just read the following code but do not understand why there is ” and also ‘ used. Thank you!
$sql='SELECT uid,name FROM users WHERE user="'.mysql_real_escape_string($_POST['login_name']).'" AND ..
Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.
Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.
Lost your password? Please enter your email address. You will receive a link and will create a new password via email.
Please briefly explain why you feel this question should be reported.
Please briefly explain why you feel this answer should be reported.
Please briefly explain why you feel this user should be reported.
This is a PHP program to write an SQL query (and store it in a string).
The target SQL looks like this:
So in PHP terms:
But you want to replace “something” with dynamic data. In this case the posted login_name — but made safe for MySQL.
A better approach is to use prepared statements.