Welcome to ShenZhenJia Knowledge Sharing Community for programmer and developer-Open, Learning and Share
menu search
person
Welcome To Ask or Share your Answers For Others

Categories

I have two choices to store my html string:

  1. turning off magic_quotes_gpc and store it directly using PDO.
  2. turning on magic_quotes_gpc and let my html string be stored with slashes using PDO. then, convert those slashes by using the function stripslashes();

I need to know the pros and cons of those two choices, and which one do you recommend? I am guessing that there is a security threat with the first choice. and load on the server with the second choice, but I need to know what the experts say.

See Question&Answers more detail:os

与恶龙缠斗过久,自身亦成为恶龙;凝视深渊过久,深渊将回以凝视…
thumb_up_alt 0 like thumb_down_alt 0 dislike
152 views
Welcome To Ask or Share your Answers For Others

1 Answer

Magic Quotes are deprecated. Don't use them. Use PDO and prepared statement instead.

As a side note you should not call to experts in this case. If the official PHP documentation says in a big red box don't use this feature, there is no question to be asked.

enter image description here


与恶龙缠斗过久,自身亦成为恶龙;凝视深渊过久,深渊将回以凝视…
thumb_up_alt 0 like thumb_down_alt 0 dislike
Welcome to ShenZhenJia Knowledge Sharing Community for programmer and developer-Open, Learning and Share

548k questions

547k answers

4 comments

86.3k users

...