Re: escaped characters problem
| From: | Jordi Sánchez | Date: | Tue, 20 Jun 2000 02:48:28 +0000 |
| Subject: | Re: escaped characters problem | ||
| References: | 1 | Groups: | php.db |
| Request: | Send a blank email to php-db+get-504@lists.php.net to get a copy of this message | ||
On Mon, 19 Jun 2000, Lez Lytollis wrote:
> I have a written a simple news input interface for our admin staff to add
> articles to our website. When they have an article name containing a single
> quote, the string is cut off at that point on generation of the sql string.
>
> example
> ---------
>
> original typed entry in description field: Lez's quote test
> echoed $description value: Lez\'s quote test
> $strsql = "INSERT INTO news (description) VALUES ( '$description' )";
> echoed $strsql value: Lez\
>
> Can anyone tell me what is going on and how I can fix it?
What is going on is really simple. SQL is interpeting this:
INSERT INTO news (description) VALUES('Lez's quote test');
and so, the single quote in "Lez's" is breaking the semantics of the sql
expresion and can't interpret the query as you'd want because it doesn't
know how to deal with "s quote test'".
If you only want to insert values having quotes, then you can try using
double-quotes insted of single quotes.
Then $strsql will look like:
$strsql = "INSERT INTO news (descripion) VALUES (\"$description\")";
This should do.
>
> Thanks in advance
>
> Lez
>
-=-=-=-==-==-==-====-======================-====-==-==-==-=-=-=-
Jordi Sanchez <jsanchez@espanaoline.com>
kinda CGI programmer && sysadm - Phone: +34677671578