SQLæãä½ãéãã¨ããããã©ã®æ¹æ³ãããå¼·ããããç°¡æãªSQLã¤ã³ã¸ã§ã¯ã·ã§ã³å¯¾çãªã®ã調ã¹ã¦ããã®ã§ãããã©ããã addslashes ã«ã¯ç©´ãããããããPrepared Statement ããã¾ã㯠mysql_real_escape_string() ãªã©ã®ãã¼ã¿ãã¼ã¹å°ç¨ã¨ã¹ã±ã¼ã颿°ã使ç¨ããã®ããããããã¨ã®è¨äºãçºè¦ã âPHP å©ç¨æã« Shift_JIS ã§ addslashes() ã«ããã¨ã¹ã±ã¼ãå¦çã«ãSQL ã¤ã³ã¸ã§ã¯ã·ã§ã³å¯è½ãªç©´ âaddslashesã«ããã¨ã¹ã±ã¼ãå¦çã¯æ¢ãã¾ããã âaddslashesã¯ä½¿ã£ã¦ããï¼ä½¿ã£ã¡ããã¡ï¼ ã¨ãããã Prepared Statement ã§ãã£ã¦ã¿ããããªã¨ã 調ã¹ã¦ã¡ã¢ã ã»query() ã¡ã½ããã§ã®ä¾ $sql = âSELECT * FROM (ãã¼ãã«å) WHERE (ã«ã©ã å) = ?â;
{{#tags}}- {{label}}
{{/tags}}