Re: Quotes
| From: | (Chris Adams) | Date: | Sun, 14 Jan 2001 19:04:59 +0000 |
| Subject: | Re: Quotes | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-34492@lists.php.net to get a copy of this message | ||
On 14 Jan 2001 10:38:12 -0800, rodrigo <rodrigo@shreve.net> wrote:
>However, yesterday I was typing in an English name that had a single
>quote (say, like O'reilly) and the SQL querie was all wrong.
You need to escape the special characters (' becomes '' or \' depending on
database flavor). PHP's built-in addslashes() function does this nicely. If
your database complains about something addslashes() doesn't catch, there may
also be a db-specific function like mysql_escape_string() which ensures that
the string is safe to use in a query.