How to add mysql_real_escape_string() after str_replace()?
$s='+'.str_replace(' ',' +',rawurldecode($_GET['search']));
$sql = '
SELECT * from table
where match
(keywords)
AGAINST
('".mysql_real_escape_string($s)."' IN BOOLEAN MODE)
order by date desc
limit '.mysql_real_escape_string($_GET['number']).',10
';
Is this the correct way to write the mysql_real_escape_string() in such a mysql full text search? Thanks.