4 ms·
The title and description don't match the code there. As you say, the code sample is actually to prevent XSS, not SQL injection. stripslashes is used to undo t
by midnightmonster 11y ago
The title and description don't match the code there. As you say, the code sample is actually to prevent XSS, not SQL injection.
stripslashes is used to undo the effects of PHP's old, terrible magic quotes misfeature, b/c the original author (probably not the blog post author) is assuming that $input is coming from the user via GET or POST.