addcslashes
addcslashes — Quote string with slashes in a C style
Description
string addcslashes ( string str, string charlist)
It adds backslashes to the characters in the string specified as second parameter
<?php
$fname = $_POST[’fname’];
$lname = $_POST[’lname’];
$fname = addcslashes($fname,”‘”);
$lname = addcslashes($lname,”‘”);
$qeury = “SELECT * FROM users where fname=”.$fname.” AND lname =”‘.$lname.’”;
/// If users input the fname as abc’ced then the our string will be abc\’ced
?>
