PHP 4.0 Bug #4964: inserting "special" data fails

From: Date: Sun, 11 Jun 2000 19:31:43 +0000
Subject: PHP 4.0 Bug #4964: inserting "special" data fails
Groups: php.dev 
Request: Send a blank email to php-dev+get-21053@lists.php.net to get a copy of this message
From: fredo@pandora.be Operating system: NT4/Apache1.3.12 PHP version: 4.0.0 Release PHP Bug Type: ODBC related Bug description: inserting "special" data fails Ok, here goes, I don't think this is a real bug, but I can't find a solution for it, $db_query = "INSERT INTO UserInfo (Name, Email) ". "VALUE ('$username', '$email')"; $db_result = odbc_exec($db_conn, $db_query); This works smoothly as long as no value contains a "special" sign. Example, $username="Olivier D'hooghe" Several people told me to use addslashes() but that doesn't solve it, here follows the error message, Warning: SQL error: [Microsoft][ODBC Microsoft Access Driver] Syntax error (missing operator) in query expression ''Olivier D\'Hooghe', 'oli@home.net')'., SQL state 37000 in SQLExecDirect in common.php on line 101 The problem is the <'> in the username. I'm stuck.

« previous php.dev (#21053) next »