Re: $_POST in MySQL query issue...

From: Date: Fri, 17 Oct 2003 01:36:23 +0000
Subject: Re: $_POST in MySQL query issue...
References: 1  Groups: php.db php.general php.windows 
Request: Send a blank email to php-general+get-166392@lists.php.net to get a copy of this message
On Thu, 16 Oct 2003, Adam Reiswig wrote: > $sql="insert into $table set Name = '$_POST["elementName"]'"; > > Unfortunately this and every other combination I can think of, > combinations of quotes that is, does not work. I believe the source of > the problem is the quotes within quotes within quotes. I also tried: > > $sql='insert into $table set Name = '.$_POST["elementName"]; > or > $sql="insert into $table set Name = ".$_POST['elementName']; You need to quote the Name. $sql = 'insert into '.$table.' set Name = "'.addslashes($_POST['elementName']).'"'; You've done everything here that you need, no extra variables, no nothing. Register_Globals is bad -- if you can avoid using it, do so. Performance-wise, it is better to use single quotes and concat the variables outside of the quoted line. Better performance, less problems with variables not being expanded correctly. Beckman --------------------------------------------------------------------------- Peter Beckman Internet Guy beckman@purplecow.com http://www.purplecow.com/ ---------------------------------------------------------------------------

« previous php.general (#166392) next »