Re: Quotes are messign up my SQL Query, need help

From: Date: Wed, 06 Dec 2000 14:56:02 +0000
Subject: Re: Quotes are messign up my SQL Query, need help
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-28914@lists.php.net to get a copy of this message
Shane McBride [php@riversidedesigns.net] wrote: > I have a customer who keeps me on my toes. Each time I think I got the php code bullet proof, > she throws me a curve ( and she doens't even know it). > > She uploads what we call "Featured Items". The one in question now have a value like > this: > "Hun-Gan-Tse" ("I Am Going") > > It gets written to the MySQL DB just fine, and pulled from the DB for display on a web page. > The problem comes in when I/she tries to remove the item from the DB. > > Here's what I have: > //Create SQL Statement > $sql = "DELETE FROM featured WHERE title = '$sel_record'"; > > //Execute SQL query and get results > $sql_result = mysql_query($sql, $connection) or die ("Couldn't execute query"); > > I suppose all the quotes and parenthesis screw this up. Any ideas? If "Hun-Gan-Tse" ("I Am Going") is the value of $sel_record, then try using the "addslashes" method to escape all that needs to be escaped, like this: $sel_record = addslashes($sel_record); $sql = "DELETE FROM featured WHERE title = '$sel_record'"; $sql_result = mysql_query($sql, $connection) or die ("Couldn't execute query"); One other options is to look into "magic quotes" - I haven't used that myself so I'm not exactly sure what it does, but I do think it escapes quotes. HTH. -- Hardy Merrill Mission Critical Linux, Inc. http://www.missioncriticallinux.com

« previous php.general (#28914) next »