Manual Screening in the Doctrine

When you write your own SQL statements using Doctrine, how should you avoid input? In my experience, it mysql_real_escape_stringdoes not work.

+3
source share
1 answer

When mysql_real_escape_string()used correctly, it works great. Parameterized libraries such as ADODB and PDO will not work without it. I highly recommend using PDO.

+3
source

Source: https://habr.com/ru/post/1778833/


All Articles