RE: [PHP-DB] SQL query problem
| From: | Mike Dugas | Date: | Mon, 05 Jun 2000 18:32:44 +0000 |
| Subject: | RE: [PHP-DB] SQL query problem | ||
| References: | 1 | Groups: | php.db |
| Request: | Send a blank email to php-db+get-214@lists.php.net to get a copy of this message | ||
Super! A quick lookup on syntax for addslashes() on phpbuilder.com,
and tacking these above my SQL query (these are the only fields that're
multi-line text entry) solved the problem:
$engmods = addslashes($engmods);
$suspmods = addslashes($suspmods);
$intmods = addslashes($intmods);
$extmods = addslashes($extmods);
$audiomods = addslashes($audiomods);
$miscmods = addslashes($miscmods);
$futuremods = addslashes($futuremods);
Thanks again!
On Mon, 5 Jun 2000, Sam Masiello wrote:
>
> I would do an addslashes() on each of the variables that you are putting
> into your table. What this will do is automatically backslash any
> characters that need backslashes before they go into the database so that
> you avoid situations such as the one you are experiencing.
>
> Sam Masiello
> System Analyst
> Chek.Com
> (716) 853-1362 x289
> smasiello@chekinc.com
>
> -----Original Message-----
> From: Mike Dugas [mailto:mad@phobia.net]
> Sent: Monday, June 05, 2000 11:27 AM
> To: php-db@lists.php.net
> Subject: [PHP-DB] SQL query problem
>
> Hi y'all,
>
> I'm having a problem with a PHP app I've written. It takes data from form
> fields, and inserts it into the database... Simple, right? :) Well, to
> start, heres my SQL query to update the database:
>
> mysql_query ("REPLACE INTO members
> (id, username, password, fname, lname, location, aim, icq, email,
> carmake, carmodel, caryear, carengine, cartrans, carcolor,
> carinterior, engmods, suspmods, intmods, extmods, audiomods,
> miscmods, futuremods, tfmtitle)
> VALUES
> ('$id', '$username', '$password', '$fname',
> '$lname', '$location',
> '$aim', '$icq', '$email', '$carmake',
> '$carmodel', '$caryear',
> '$carengine', '$cartrans', '$carcolor',
> '$carinterior',
> '$engmods', '$suspmods', '$intmods', '$extmods',
> '$audiomods',
> '$miscmods', '$futuremods', '$tfmtitle')");
>
> Ok... Now. I have someone entering data into the fields, and its all well
> and good until he gets to the "futuremods" field, where he enters the
> following data: (without the quotes, of course)
>
> "NOS with Gen-X system, Freedom Design Strut Bar, Window Tint, Complete
> Upgraded Brake System, Andy's or FX Ground Effects Kit, RK Sport Ram Air
> Hood, RK Sport White Gauge Overlay, Aftermarket Struts, Redo Entire Stereo
> System, Red Carbon Fiber Dash Kit, RK sport Red Carbon Fiber Chevy Badges,
> Rk sport Touring Wing, GRD's TPS-TEC, Turbo"
>
> And when he clicks submit, to update his record, I turned on the
> mysql_error() statement, and he gets this:
>
> 1064: You have an error in your SQL syntax near 's or FX Ground Effects
> Kit, RK Sport Ram Air Hood, RK Sport White Gauge Overla' at line 8
>
> I understand what the problem is (the apostrophe)... But I don't
> understand WHY its a problem, exactly, or how to fix it.
>
> Anyone care to help?
>
> TIA.
>
> --
> Mike Dugas mad@phobia.net
>
>
>
> --
> PHP Database Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-db-unsubscribe@lists.php.net
> For additional commands, e-mail: php-db-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
>
--
Mike Dugas mad@phobia.net