PHP 4.0 Bug #4964: inserting "special" data fails
| From: | fredo at pandora dot be | Date: | Sun, 11 Jun 2000 19:31:43 +0000 |
| Subject: | PHP 4.0 Bug #4964: inserting "special" data fails | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-21053@lists.php.net to get a copy of this message | ||
From: fredo@pandora.be
Operating system: NT4/Apache1.3.12
PHP version: 4.0.0 Release
PHP Bug Type: ODBC related
Bug description: inserting "special" data fails
Ok, here goes, I don't think this is a real bug, but I can't find a solution for it,
$db_query = "INSERT INTO UserInfo (Name, Email) ".
"VALUE ('$username', '$email')";
$db_result = odbc_exec($db_conn, $db_query);
This works smoothly as long as no value contains a "special" sign. Example,
$username="Olivier D'hooghe"
Several people told me to use addslashes() but that doesn't solve it, here follows the error
message,
Warning: SQL error: [Microsoft][ODBC Microsoft Access Driver] Syntax error (missing operator) in
query expression ''Olivier D\'Hooghe', 'oli@home.net')'., SQL
state 37000 in SQLExecDirect in common.php on line 101
The problem is the <'> in the username. I'm stuck.