- MySQLi - Home
- MySQLi - Introduction
- MySQLi - PHP Syntax
- MySQLi - Connection
- MySQLi - Create Database
- MySQLi - Drop Database
- MySQLi - Select Database
- MySQLi - Create Tables
- MySQLi - Drop Tables
- MySQLi - Insert Query
- MySQLi - Select Query
- MySQLi - Where Clause
- MySQLi - Update Query
- MySQLi - Delete Query
- MySQLi - Like Clause
- MySQLi - Sorting Results
- MySQLi - Using Joins
- MySQLi - Handling NULL Values
- Obtaining & Using MySQLi Metadata
- MySQL - Installation
- MySQL - Administration
- MySQL - Data Types
- MySQL - Regexps
- MySQL - Transactions
- MySQL - Alter Command
- MySQL - Indexes
- MySQL - Temporary Tables
- MySQL - Clone Tables
- MySQL - Using Sequences
- MySQL - Handling Duplicates
- MySQLi Useful Resources
- MySQLi - Useful Functions
- MySQLi - Quick Guide
- MySQLi - Useful Resources
- MySQLi - Discussion
MySQLi - Real Escape String
Syntax
string mysqli_real_escape_string ( mysqli $link , string $escapestr )
Definition and Usage
It escapes special characters in a string for use in an SQL statement.
Example
Try out following example −
<?php
$servername = "localhost:3306";
$username = "root";
$password = "";
$dbname = "TUTORIALS";
$conn = new mysqli($servername, $username, $password, $dbname);
if (!$conn->real_connect($servername, $username, $password, $dbname)) {
die('Connect Error (' . mysqli_connect_errno() . ') '. mysqli_connect_error());
}
echo 'Success... ' . mysqli_get_host_info($conn) . "\n";
$id = mysqli_real_escape_string($conn, $_POST['id']);
$name = mysqli_real_escape_string($conn, $_POST['name']);
$sql = "INSERT INTO tutorials_auto (id, name)
VALUES ('$id', '$name')";
if (!mysqli_query($conn,$sql)) {
die('Error: ' . mysqli_error($conn));
}
echo "1 record added";
$conn->close();
?>
The sample output of the above code should be like this −
Success... localhost:3306 via TCP/IP 1 record added
mysqli_useful_functions.htm
Advertisements