Re: Quotes are messign up my SQL Query, need help
| From: | Matthew Ballard | Date: | Wed, 06 Dec 2000 19:37:08 +0000 |
| Subject: | Re: Quotes are messign up my SQL Query, need help | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-28960@lists.php.net to get a copy of this message | ||
When I did some quick testing, MySQL doesn't care if you have " when they are enclosed in ''. If the deleted value is being submitted using a form, check if the quotes are automatically being escaped out. If it yes, use stripslashes on the variable. The easiest way to check if you need to do this is to output the sql statement, and check for anything that shouldn't be there.
Matthew
At 09:48 AM 12/6/2000 -0500, you wrote:
I have a customer who keeps me on my toes. Each time I think I got the php code bullet proof, she throws me a curve ( and she doens't even know it). She uploads what we call "Featured Items". The one in question now have a value like this: "Hun-Gan-Tse" ("I Am Going") It gets written to the MySQL DB just fine, and pulled from the DB for display on a web page. The problem comes in when I/she tries to remove the item from the DB. Here's what I have: //Create SQL Statement $sql = "DELETE FROM featured WHERE title = '$sel_record'"; //Execute SQL query and get results $sql_result = mysql_query($sql, $connection) or die ("Couldn't execute query"); I suppose all the quotes and parenthesis screw this up. Any ideas? TIA, Shane