

(PECL maxdb >= 1.0)

maxdb_real_escape_string -- maxdb::real_escape_stringEscapes special characters in a string for use in an SQL statement, taking into account the current charset of the connection



maxdb_real_escape_string ( resource $link , string $escapestr ) : string


maxdb::real_escape_string ( string $escapestr ) : string

This function is used to create a legal SQL string that you can use in an SQL statement. The string escapestr is encoded to an escaped SQL string, taking into account the current character set of the connection.

Characters encoded are ', ".


Returns an escaped string.


Example #1 面向对象风格

= new maxdb("localhost""MONA""RED""DEMODB");

/* check connection */
if (maxdb_connect_errno()) {
printf("Connect failed: %s\n"maxdb_connect_error());

$maxdb->query("CREATE TABLE temp.mycity LIKE");

$city "'s Hertogenbosch";

/* this query will fail, cause we didn't escape $city */
if (!$maxdb->query("INSERT into temp.mycity VALUES ('11111','$city','NY')")) {
printf("Error: %s\n"$maxdb->sqlstate);

$city $maxdb->real_escape_string($city);

/* this query with escaped $city will work */
if ($maxdb->query("INSERT into temp.mycity VALUES ('22222','$city','NY')")) {
printf("%d Row inserted.\n"$maxdb->affected_rows);


Example #2 过程化风格


/* check connection */
if (maxdb_connect_errno()) {
printf("Connect failed: %s\n"maxdb_connect_error());

maxdb_query($link"CREATE TABLE temp.mycity LIKE");

$city "'s Hertogenbosch";

/* this query will fail, cause we didn't escape $city */
if (!maxdb_query($link"INSERT into temp.mycity VALUES ('11111','$city','NY')")) {
printf("Error: %s\n"maxdb_sqlstate($link));

$city maxdb_real_escape_string($link$city);

/* this query with escaped $city will work */
if (maxdb_query($link"INSERT into temp.mycity VALUES ('22222','$city','NY')")) {
printf("%d Row inserted.\n"maxdb_affected_rows($link));



Warning: maxdb_query(): -5016 POS(43) Missing delimiter: ) <...>
Error: 42000
1 Row inserted.


php cubrid mysql 兼容性函数 return the current cubrid connection charsetphp cubrid 函数 execute a prepared sql statementphp cubrid 函数 return the current cubrid connection charsetphp cubrid 函数 bind a lob object or a string as a lob object to a prepared statement as parametersphp cubrid mysql 兼容性函数 escape special characters in a string for use in an sql statementphp ibm db2 函数 returns a string containing the sqlstate returned by an sql statementphp ibm db2 函数 returns a string containing the last sql statement error messagephp dbx 函数 escape a string so it can safely be used in an sql statementphp ingres 函数 escape special characters for use in a queryphp maxdb 函数 returns the default character set for the database connectionphp maxdb 函数 returns a string representing the type of connection usedphp maxdb 函数 prepare an sql statement for executionphp maxdb 函数 escapes special characters in a string for use in an sql statement taking into account the current charset of the connectionphp maxdb 函数 returns a string description for last statement errorphp maxdb 函数 fetch results from a prepared statement into the bound variablesphp maxdb 函数 initializes a statement and returns an resource for use with maxdb stmt preparephp maxdb 函数 prepare an sql statement for executionphp maxdb 函数 returns the thread id for the current connectionphp sqlite 函数 escapes a string for use as a query parameterphp mysqlnduhconnection escapes special characters in a string for use in an sql statement taking into account the current charset of the connection