Quote:
Originally Posted by punky
Sanitising input can mean almost anything but usually it means escaping characters. This means it converts ' to \' so the query remains safe to be executed by MySQL
Its de-escaped (either automatically or manually, I can't remember now its been a while) when its retrieved back onto the page.
|
Thought you meant that. Surely some of the bigger layers support actual parametrisation?