Error checking and escaping before running a query (MySQL)
| From: | Dave Watkinson | Date: | Wed, 08 Aug 2001 07:18:21 +0000 |
| Subject: | Error checking and escaping before running a query (MySQL) | ||
| Groups: | php.db | ||
| Request: | Send a blank email to php-db+get-11131@lists.php.net to get a copy of this message | ||
Hi all
I have a searchbox that throws a wobbly when certain characters are
entered into it - basically the user is supposed to enter a
space-delimited list of words to search for, and then I create an array
from it and turn it into an OR etc query.
What I initially did was replace all commas with spaces, but I've
realised that double-quotes mess it up too.
The command I used for the spaces is
$searchbox = ereg_replace(" ," ," ", $searchbox);
I tried
$searchbox = ereg_replace(" \"" ," ", $searchbox);
but the page shows an error of
Warning: REG_EPAREN: in
d:\apache\htdocs\dev\code\can_search_quick.php on line 22
there's a parse error if I don't escape the ", so what can I do? I know
how to do it in VB!
I searched PHP.net, but could only find an old bug report that advised
escaping special characters!
Help!
Thanks in advance
Dave