<?xml version="1.0" encoding="windows-1252"?>
<node id="440817" title="Re^4: DBH Insert of Binary Data" created="2005-03-18 17:28:52" updated="2005-03-19 12:23:45">
<type id="11">
note</type>
<author id="157432">
Joost</author>
<data>
<field name="doctext">
I mostly agree, but AFAIK, the $dbh-&gt;quote() method is (or should be) implemented by the specific DBD driver and should always escape correctly. Now, there might be situations or database where you can't just insert a quoted string in a BLOB, but SQL injection should not be possible with a $dbh-&gt;quote()d string.
&lt;p&gt;
&lt;del&gt;The top post should remove the quotes around the quoted string, though, as $dbh-&gt;quote already provides them.&lt;/del&gt; Never mind, there aren't any.
&lt;p&gt;
&lt;!-- Node text goes above. Div tags should contain sig only --&gt;
&lt;div class="pmsig"&gt;&lt;div class="pmsig-157432"&gt;
&lt;em&gt;[id://149675|"What should it profit a man, if he should win a flame war, yet lose his cool?"]&lt;/em&gt;

&lt;/div&gt;&lt;/div&gt;</field>
<field name="root_node">
440788</field>
<field name="parent_node">
440801</field>
</data>
</node>
