On Mon, February 18, 2008 10:19 pm, Bastien Koert wrote: > mysql_real_escape_string() Yes. > addslashes() No, not right for different charsets. See above. > htmlentities() Completely and wildly inappropriate. Might as well use a cannon to slice a tomato. -- Some people have a "gift" link here. Know what I want? I want you to buy a CD from some indie artist. http://cdbaby.com/from/lynch Yeah, I get a buck. So? -- PHP General Mailing List (http://www.php.net/) To unsubscribe, visit: http://www.php.net/unsub.php