You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Sublime开发Web时遇致命错误:调用未定义mysql_real_escape_string()求帮助

Fixing the fatal error: Uncaught Error: call to undefined mysql_real_escape_string() in Your Login System

Hey there, let's get this error sorted out so you can get back to building your login feature!

Why This Error Happens

The mysql_real_escape_string() function belongs to PHP's old, deprecated MySQL extension. This extension was completely removed in PHP 7.0 and later versions—so if you're running a modern PHP setup, this function no longer exists, hence the error.

Solutions to Fix This

Here are the most reliable ways to replace that old function and secure your login system properly:

1. Switch to the MySQLi Extension (Procedural or Object-Oriented)

MySQLi is the updated replacement for the old MySQL extension, and it includes a direct replacement for the escape function: mysqli_real_escape_string(). Just make sure you pass your database connection as the first parameter!

Example code snippet:

// First, establish your database connection
$dbConn = mysqli_connect("localhost", "your_username", "your_password", "your_database");

// Check if the connection worked
if (!$dbConn) {
    die("Connection failed: " . mysqli_connect_error());
}

// Escape user input using mysqli_real_escape_string
$username = mysqli_real_escape_string($dbConn, $_POST['username']);
$password = mysqli_real_escape_string($dbConn, $_POST['password']);

2. Use Prepared Statements (The Most Secure Option)

Manual escaping is better than nothing, but prepared statements are the gold standard for preventing SQL injection attacks. They handle input sanitization automatically, so you don't have to worry about escaping manually.

Here's a complete MySQLi prepared statement example for your login system:

$dbConn = mysqli_connect("localhost", "your_username", "your_password", "your_database");

if (!$dbConn) {
    die("Connection failed: " . mysqli_connect_error());
}

// Prepare your SQL query with placeholders (?)
$stmt = mysqli_prepare($dbConn, "SELECT * FROM users WHERE username = ? AND password = ?");

// Bind your input variables to the placeholders ( "ss" means two string values )
mysqli_stmt_bind_param($stmt, "ss", $inputUsername, $inputPassword);

// Assign the user input to variables
$inputUsername = $_POST['username'];
$inputPassword = $_POST['password'];

// Important: Always store passwords as hashes, not plain text!
// When registering users, use password_hash($_POST['password'], PASSWORD_DEFAULT)
// Then verify with password_verify() like this:
// if (password_verify($inputPassword, $dbPassword)) { ... }

// Execute the prepared statement
mysqli_stmt_execute($stmt);

// Get the result
$result = mysqli_stmt_get_result($stmt);

// Check if a matching user exists
if (mysqli_num_rows($result) > 0) {
    $user = mysqli_fetch_assoc($result);
    // Verify the password hash
    if (password_verify($inputPassword, $user['password'])) {
        echo "Login successful!";
        // Add your post-login logic here
    } else {
        echo "Invalid username or password";
    }
} else {
    echo "Invalid username or password";
}

// Clean up
mysqli_stmt_close($stmt);
mysqli_close($dbConn);

3. Try the PDO Extension (Alternative to MySQLi)

PDO (PHP Data Objects) is another great option—it supports multiple database types and has a clean, object-oriented syntax. Here's a quick PDO example for your login:

try {
    $pdo = new PDO("mysql:host=localhost;dbname=your_database", "your_username", "your_password");
    $pdo->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION);

    // Prepare and execute the query
    $stmt = $pdo->prepare("SELECT * FROM users WHERE username = ?");
    $stmt->execute([$_POST['username']]);
    $user = $stmt->fetch(PDO::FETCH_ASSOC);

    if ($user && password_verify($_POST['password'], $user['password'])) {
        echo "Login successful!";
    } else {
        echo "Invalid credentials";
    }
} catch(PDOException $e) {
    echo "Error: " . $e->getMessage();
}

// Close the connection
$pdo = null;

Quick Reminder

Never store plain-text passwords in your database! Always use password_hash() when creating user accounts and password_verify() during login to check the password against the stored hash.

内容的提问来源于stack exchange,提问作者Megamoneyid

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 06:46:03