Re: Re: Building a query string
| From: | Ed Curtis | Date: | Wed, 03 Dec 2003 16:52:57 +0000 |
| Subject: | Re: Re: Building a query string | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-171691@lists.php.net to get a copy of this message | ||
> To answer the question, $query_str.=" AND garage = '$garage' ";
>
> BUT. If $garage is an id (numeric), then you should use
> $garage=abs($garage) first in order to defeat SQL injection. If it's a
> string, well, say so and we'll tell you what to do (a lot to explain,
> and not useful if it's an ID).
>
> Bogdan
All values pulled from $_POST are strings such as $garage = "Attached 2
Car" or "Detached 1 Car", etc. There are a few options that will be based
on a checkbox. If the box is checked it means you want that option
included in the query as well, i.e. (fireplace == "yes".) If the box is
not checked it means no, i.e (fireplace == "no".)
Thanks,
Ed