mysql_real_escape_string is used for SQL statements. Is it enough for database security alone? For example with get_magic_quotes_gpc() we have use stripslashes. Is there any issue that we have to know about using other function with mysql_real_escape_string ?
Thanks in advance
mysql_real_escape_string is used for SQL statements. Is it enough for database security alone? For
Share
If you want to have a more secure database, simply escaping a string is not enough. This will definitely help in regards to SQL injection attacks, but there are a host of other methods to compromise a database.
Some pointers:
These are generally good practice and you should be aware of issues for databases outside the scope of just SQL injection attacks.