Re: SQL query problem

From: Date: Mon, 05 Jun 2000 15:48:34 +0000
Subject: Re: SQL query problem
Groups: php.db 
Request: Send a blank email to php-db+get-207@lists.php.net to get a copy of this message
The problem is that your query ends up looking like the following (massively trimmed): REPLACE INTO members (id, futermods) VALUES ('myidvalue', 'a string'with a quote') So, MySQL is choking because that last part is invalid since "a string" is the string, and then what is "with a quote'" ??? To fix this you need to do something like this first: $futermods = ereg_replace("'", "\'", $futermods); to escape the single quotes in your strings. You should do this for all fields that could have a single quote in them... This would make the above query look like this: REPLACE INTO members (id, futermods) VALUES ('myidvalue', 'a string\'with a quote') which MySQL can handle. good luck! -philip In article <Pine.BSF.4.10.10006051123100.19684-100000@arachno.phobia.net>, Mike Dugas <mad@phobia.net> wrote: >Hi y'all, >I'm having a problem with a PHP app I've written. It takes data from form >fields, and inserts it into the database... Simple, right? :) Well, to >start, heres my SQL query to update the database: >mysql_query ("REPLACE INTO members > (id, username, password, fname, lname, location, aim, icq, email, > carmake, carmodel, caryear, carengine, cartrans, carcolor, > carinterior, engmods, suspmods, intmods, extmods, audiomods, > miscmods, futuremods, tfmtitle) > VALUES > ('$id', '$username', '$password', '$fname', > '$lname', '$location', > '$aim', '$icq', '$email', '$carmake', >'$carmodel', '$caryear', > '$carengine', '$cartrans', '$carcolor', '$carinterior', > '$engmods', '$suspmods', '$intmods', '$extmods', >'$audiomods', > '$miscmods', '$futuremods', '$tfmtitle')"); >Ok... Now. I have someone entering data into the fields, and its all well >and good until he gets to the "futuremods" field, where he enters the >following data: (without the quotes, of course) >"NOS with Gen-X system, Freedom Design Strut Bar, Window Tint, Complete >Upgraded Brake System, Andy's or FX Ground Effects Kit, RK Sport Ram Air >Hood, RK Sport White Gauge Overlay, Aftermarket Struts, Redo Entire Stereo >System, Red Carbon Fiber Dash Kit, RK sport Red Carbon Fiber Chevy Badges, >Rk sport Touring Wing, GRD's TPS-TEC, Turbo" >And when he clicks submit, to update his record, I turned on the >mysql_error() statement, and he gets this: >1064: You have an error in your SQL syntax near 's or FX Ground Effects >Kit, RK Sport Ram Air Hood, RK Sport White Gauge Overla' at line 8 >I understand what the problem is (the apostrophe)... But I don't >understand WHY its a problem, exactly, or how to fix it. >Anyone care to help? >TIA.

« previous php.db (#207) next »