I do not know where the problem is that I I add a Is there any string functions that can solve my problem? , use ... ... or better, use a binded parameter with something like PDO. By the way, there is no reason why & gt; and ( in my MySQL database). addslashes ($ str) , but it can still leave the quotation marks unsecured.
every Once you exit the string in a query, use it!
& gt; and ) will be inserted into your database which I can think of, without any meaning inside the string \ .
Comments
Post a Comment