Re: Re: Building a query string

From: Date: Wed, 03 Dec 2003 16:52:57 +0000
Subject: Re: Re: Building a query string
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-171691@lists.php.net to get a copy of this message
> To answer the question, $query_str.=" AND garage = '$garage' "; > > BUT. If $garage is an id (numeric), then you should use > $garage=abs($garage) first in order to defeat SQL injection. If it's a > string, well, say so and we'll tell you what to do (a lot to explain, > and not useful if it's an ID). > > Bogdan All values pulled from $_POST are strings such as $garage = "Attached 2 Car" or "Detached 1 Car", etc. There are a few options that will be based on a checkbox. If the box is checked it means you want that option included in the query as well, i.e. (fireplace == "yes".) If the box is not checked it means no, i.e (fireplace == "no".) Thanks, Ed

« previous php.general (#171691) next »