PHP 防止 SQL 注入的函数

function cleanuserinput($dirty){
    if (get_magic_quotes_gpc()) {
        $clean = mysql_real_escape_string(stripslashes($dirty));     
    }else{
        $clean = mysql_real_escape_string($dirty);  
    } 
    return $clean;
}

编程技巧