user342391
user342391

Reputation: 7827

htmlspecialchars or mysql_real_escape_string?

I am unsure which one to use in this situation???

$query1 = "SELECT * FROM messages WHERE 
messages.custid='".htmlspecialchars($_SESSION['customerid'])."' 
ORDER BY messages.id LIMIT $start, $limit ";

Upvotes: 1

Views: 985

Answers (2)

Tokk
Tokk

Reputation: 4502

mysql_real_escape_string() is made especialy for Mysql Tables, as the name indicates ;-)

Upvotes: 0

Zak
Zak

Reputation: 25205

use mysql_real_escape_string .. But really, don't do that

instead, install Pear's PDO library, then use a prepared statement for your query

Upvotes: 2

Related Questions