The magic_quotes_gpc (magic quotes switch)

php role magic_quotes_gpc function is determined parsing prompt the user data ,

Such as including: post, get, cookie over the data to increase the escape character "\" to ensure that these data do not cause programs, in particular database statements fatal mistake because of pollution caused by the emergence of special characters.

= In The magic_quotes_gpc the On the case, if the input data has

a single quote ( '), double quote ( "), backslash (\) and NULL (NULL characters) characters and the like will be backslash These escape It's required,

If this option is Off , then we shall have to call this function addslashes to increase the escape string.

It is for this option must be On, but letting users configure the contradiction, delete this option in PHP6 in all programming need to be in at magic_quotes_gpc = Off.

In such an environment only if the user's data does not escape the consequences of not merely procedural error. The same database is cause danger injection attacks.

So from now on we do not rely on this to On again up.

Guess you like

Origin www.cnblogs.com/wangshuazi/p/11117645.html