2011-03-23 73 views
0

IM试图防止SQL注入与

mysql_real_escape_string($value) 

这里是我的代码,但它似乎是我得到一个空值,

$this->name_safe = mysqli_real_escape_string($this->name,$this->link); 

      $this->query = "INSERT INTO student (complete_name, date_birth, gender, email, student_status) 
      VALUES ('$this->name_safe', '$this->date', '$this->gender', '$this->email_1', 'current')"; 

? thx

回答