(PHP 4 >= 4.0.3, PHP 5)
mysql_escape_string —Escapes a string for use in a mysql_query
This function was deprecated in PHP 4.3.0, and itand the entireoriginal MySQL extension was removed in PHP 7.0.0.Instead, use either the actively developedMySQLi orPDO_MySQL extensions.See also theMySQL: choosing an API guide.Alternatives to this function include:
This function will escape theunescaped_string, so that it is safe to place it in amysql_query(). This function is deprecated.
This function is identical tomysql_real_escape_string() except thatmysql_real_escape_string() takes a connection handler and escapes the string according to the current character set.mysql_escape_string() does not take a connection argument and does not respect the current charset setting.
unescaped_stringThe string that is to be escaped.
Returns the escaped string.
Example #1mysql_escape_string() example
<?php
$item="Zak's Laptop";
$escaped_item=mysql_escape_string($item);
printf("Escaped string: %s\n",$escaped_item);
?>The above example will output:
Escaped string: Zak\'s Laptop
Note:
mysql_escape_string() does not escape
%and_.
