Re: Quotes are messign up my SQL Query, need help
| From: | Hardy Merrill | Date: | Wed, 06 Dec 2000 14:56:02 +0000 |
| Subject: | Re: Quotes are messign up my SQL Query, need help | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-28914@lists.php.net to get a copy of this message | ||
Shane McBride [php@riversidedesigns.net] wrote:
> I have a customer who keeps me on my toes. Each time I think I got the php code bullet proof,
> she throws me a curve ( and she doens't even know it).
>
> She uploads what we call "Featured Items". The one in question now have a value like
> this:
> "Hun-Gan-Tse" ("I Am Going")
>
> It gets written to the MySQL DB just fine, and pulled from the DB for display on a web page.
> The problem comes in when I/she tries to remove the item from the DB.
>
> Here's what I have:
> //Create SQL Statement
> $sql = "DELETE FROM featured WHERE title = '$sel_record'";
>
> //Execute SQL query and get results
> $sql_result = mysql_query($sql, $connection) or die ("Couldn't execute query");
>
> I suppose all the quotes and parenthesis screw this up. Any ideas?
If
"Hun-Gan-Tse" ("I Am Going")
is the value of $sel_record, then try using the "addslashes"
method to escape all that needs to be escaped, like this:
$sel_record = addslashes($sel_record);
$sql = "DELETE FROM featured WHERE title = '$sel_record'";
$sql_result = mysql_query($sql, $connection)
or die ("Couldn't execute query");
One other options is to look into "magic quotes" - I haven't
used that myself so I'm not exactly sure what it does, but I
do think it escapes quotes.
HTH.
--
Hardy Merrill
Mission Critical Linux, Inc.
http://www.missioncriticallinux.com