Re: Re: I am probably dumb but why isn't this inserting stuff into my DB?

From: Date: Sat, 06 Jul 2002 03:28:06 +0000
Subject: Re: Re: I am probably dumb but why isn't this inserting stuff into my DB?
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-105793@lists.php.net to get a copy of this message
OK, I have magic_quotes on though so useless lecture thanks for the advice -- JJ Harrison webmaster@tececo.com www.tececo.com "Miguel Cruz" <mnc@stoic.net> wrote in message news:Pine.LNX.4.44.0207052217030.3861-100000@stoic.net... > On Sat, 6 Jul 2002, JJ Harrison wrote: > > $query = "INSERT INTO tececo_stats values ('', $id, $visited, $time, > > $remote_dns, $remote_ip, $referer, $browser, $system)"; > > mysql_query($query); > > You should always do the following if you are having trouble: > > 1) print out $query and try it yourself at the mysql command line. > > 2) print mysql_error(). > > In this case I think the problem is that you've failed to quote the > strings in your INSERT. Try something like > > INSERT INTO tececo_stats values ('', '$id', '$visited', > '$time' ... > > Also note that as it stands, I could potentially make big trouble for you > by putting clever values into HTTP_REFERER (which is totally under my > control as a visitor to your site). So make sure you mysql_escape_string > or addslashes those values (unless you have magic_quotes turned on, in > which case you can ignore this lecture). > > miguel > >

« previous php.general (#105793) next »