Re: SQL query problem
| From: | (Philip Hallstrom) | Date: | Mon, 05 Jun 2000 15:48:34 +0000 |
| Subject: | Re: SQL query problem | ||
| Groups: | php.db | ||
| Request: | Send a blank email to php-db+get-207@lists.php.net to get a copy of this message | ||
The problem is that your query ends up looking like the following
(massively trimmed):
REPLACE INTO members (id, futermods)
VALUES ('myidvalue', 'a string'with a quote')
So, MySQL is choking because that last part is invalid since "a string"
is the string, and then what is "with a quote'" ???
To fix this you need to do something like this first:
$futermods = ereg_replace("'", "\'", $futermods);
to escape the single quotes in your strings. You should do this for all
fields that could have a single quote in them...
This would make the above query look like this:
REPLACE INTO members (id, futermods)
VALUES ('myidvalue', 'a string\'with a quote')
which MySQL can handle.
good luck!
-philip
In article <Pine.BSF.4.10.10006051123100.19684-100000@arachno.phobia.net>,
Mike Dugas <mad@phobia.net> wrote:
>Hi y'all,
>I'm having a problem with a PHP app I've written. It takes data from form
>fields, and inserts it into the database... Simple, right? :) Well, to
>start, heres my SQL query to update the database:
>mysql_query ("REPLACE INTO members
> (id, username, password, fname, lname, location, aim, icq, email,
> carmake, carmodel, caryear, carengine, cartrans, carcolor,
> carinterior, engmods, suspmods, intmods, extmods, audiomods,
> miscmods, futuremods, tfmtitle)
> VALUES
> ('$id', '$username', '$password', '$fname',
> '$lname', '$location',
> '$aim', '$icq', '$email', '$carmake',
>'$carmodel', '$caryear',
> '$carengine', '$cartrans', '$carcolor', '$carinterior',
> '$engmods', '$suspmods', '$intmods', '$extmods',
>'$audiomods',
> '$miscmods', '$futuremods', '$tfmtitle')");
>Ok... Now. I have someone entering data into the fields, and its all well
>and good until he gets to the "futuremods" field, where he enters the
>following data: (without the quotes, of course)
>"NOS with Gen-X system, Freedom Design Strut Bar, Window Tint, Complete
>Upgraded Brake System, Andy's or FX Ground Effects Kit, RK Sport Ram Air
>Hood, RK Sport White Gauge Overlay, Aftermarket Struts, Redo Entire Stereo
>System, Red Carbon Fiber Dash Kit, RK sport Red Carbon Fiber Chevy Badges,
>Rk sport Touring Wing, GRD's TPS-TEC, Turbo"
>And when he clicks submit, to update his record, I turned on the
>mysql_error() statement, and he gets this:
>1064: You have an error in your SQL syntax near 's or FX Ground Effects
>Kit, RK Sport Ram Air Hood, RK Sport White Gauge Overla' at line 8
>I understand what the problem is (the apostrophe)... But I don't
>understand WHY its a problem, exactly, or how to fix it.
>Anyone care to help?
>TIA.