我只想知道我是否做得对。htmlentities mysql_real_escape_string
PHP
<?php
if(isset($_POST['email']) && isset($_POST['password'])) {
$email = htmlentities(mysql_real_escape_string($_POST['email']));
// then hash password
}
?>
HTML
<form action="" method="POST">
<input type="email" name="email" />
<input type="password" name="password" />
<input type="submit" name="Login" />
</form>
是好与mysql_real_escape_string
做htmlentities()
在一起吗?
或我需要做什么?
可能重复的[htmlentities和mysql_real_escape_string](http://stackoverflow.com/questions/11983757/htmlentities-and-mysql-real-escape-string) – hakre