Re: Re: $_POST in MySQL query issue...
| From: | Peter Beckman | Date: | Fri, 17 Oct 2003 01:38:13 +0000 |
| Subject: | Re: Re: $_POST in MySQL query issue... | ||
| References: | 1 2 | Groups: | php.db php.general php.windows |
| Request: | Send a blank email to php-general+get-166393@lists.php.net to get a copy of this message | ||
On Fri, 17 Oct 2003, BAO RuiXian wrote:
> I see you can achieve this by two ways:
>
> 1. Take out all the inside quotes (single or double) like the following:
>
> $sql="insert into $table set Name = $_POST[elementName]";
This is bad. Using no quotes MAY work, but it is considered a "BARE WORD"
and not an actual string.
$sql='insert into '.$table.' set Name =
"'.addslashes($_POST['elementName']).'"';
is the (more) correct way to do this.
> 2. Use a temporary variable for $_POST[elementName], like $elementName
> = $_POST[elementName], then continute use your original SQL sentence
> when the register_globals was on.
Waste (albeit very minor) of variable space. Concat them.
Beckman
---------------------------------------------------------------------------
Peter Beckman Internet Guy
beckman@purplecow.com http://www.purplecow.com/
---------------------------------------------------------------------------