Re: UPDATE MySQL

From: Date: Wed, 13 Nov 2002 22:18:18 +0000
Subject: Re: UPDATE MySQL
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-124329@lists.php.net to get a copy of this message
I can see two things that are not correct in the statement: First, the date you're setting is in UNIX format--but MySQL wont' like that. You need to use FROM_UNIXTIME. Second, the username is a string (I guess), but it's not within quotation marks. $myquery = "UPDATE penpals SET lastaccess=FROM_UNIXTIME($lastaccessdate) WHERE ID='$myuserid'"; Two notes: The MySQL extension does not normally print out errors. You need to explicity call mysql_error() to do that. In this case, you can add it after the call to mysql_query(), e.g.: die (mysql_error()); Also, you are passing HTTP data directly to MySQL. This can allow a malicious user to insert potentially "evil" code in your call and cause all sorts of damage. I suggest you consider filtering that information using one of the many methods available. Marco -- ------------ php|architect - The magazine for PHP Professionals The first monthly worldwide magazine dedicated to PHP programmers Come visit us at http://www.phparch.com!

« previous php.general (#124329) next »