Is this a good way to prevent SQL injection before running a database query?
$name = mysql_real_escape_string(stripslashes($name));
$age = mysql_real_escape_string(stripslashes($age));
$location = mysql_real_escape_string(stripslashes($location));
Thanks in advance!
This answers it well:
So to be on safer side, don’t rely on
mysql_real_escape_stringalone, using prepared statements is much better.