php mysql html 转义字符串,PHP& MySQL输入字符串转义问题

include("database.php");

function security_sql($x){

return mysql_real_escape_string(trim(stripslashes($x)));

}

$title = security_sql($_POST["article_title"]);

$first_name = security_sql($_POST["article_author"]);

$description = security_sql($_POST["article_summary"]);

$category = security_sql($_POST["article_category"]);

$article = security_sql($_POST["article_body_text"]);

$article_html = security_sql($_POST["article_body_html"]);

$resource_box = security_sql($_POST["article_bio_text"]);

$resource_box_html = security_sql($_POST["article_bio_html"]);

$keywords = security_sql($_POST["article_keywords"]);

$email = security_sql($_POST["article_email"]);

// Writes fine to text file

$fp = fopen('test.txt', 'a');

fwrite($fp, $title."n");

fwrite($fp, $article."nnnn");

fclose($fp);

// BUT DOESNT WORK FINE WITH MYSQL

mysql_query("INSERT INTO articles (first_name, email, title, description, article, article_html, category, resource_box, resource_box_html, keywords, distributor, distributor_host) values (

'".$first_name."',

'".$email."',

'".$title."',

'".$description."',

'".$article."',

'".$article_html."',

'".$category."',

'".$resource_box."',

'".$resource_box_html."',

'".$keywords."',

'isnare',

'".$_SERVER['REMOTE_ADDR']."'

)") or die(mysql_error());

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值