php 转义数据库

<?php
        /*
                addslashes()        在预定义字符串前添加反斜杠
                stripslashes()  把转义字符串前的反斜杠删除
                get_magic_quotes_gpc 获得PHP.INI中是否开启自动转义
        */
        //phpinfo();
        echo "<pre>";
        print_r(ini_get_all());
        if(!get_magic_quotes_gpc()){
                $cname = addslashes($_GET['cname']);
                $uname = addslashes($_GET['uname']);
        }else{
                $cname = $_GET['cname'];
                $uname = $_GET['uname'];
        }
        echo $cname;
        echo "
";
        echo stripslashes($cname);
        $mysqli = new mysqli('localhost','root','123456','edu');
        $mysqli->query('set names gbk');
        $sql = "insert into user (cname,uname) values('$cname','$uname')";
        $mysqli->query($sql);
        //echo $cname;
?>
        <form action='' method='get'>
                课程名<input type="text" name="cname">

                学员名<input type="text" name="uname">

                <input type="submit" value="提交">
        </form>

猜你喜欢

转载自zzxy001.iteye.com/blog/2020911