Re: Apostrophes/SQL Statements

From: Date: Mon, 15 May 2000 10:09:12 +0000
Subject: Re: Apostrophes/SQL Statements
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-58@lists.php.net to get a copy of this message
Andrej Trobentar wrote: > > Emile Axelrad wrote: > > > I'm getting problems with my SQL Statements where the data has apostrophes > > [single quotes]. It messes up the insertion procedure - what should I do? > > How do I get rid of the single quotes from a string? > > > > Cheers for your help! I know its an easy question but I can't find the > > proper thing to do on it... > > > > - Emile Axelrad > > Maybe this example will help you : > print '<PARAM NAME="text1" VALUE="' . $ime . > '">'; > > or this one > $stmt = OCIParse($c,"select * from imenik where PRIIMEK='$priimek'"); Wuups!! But this will produce an invalid SQL statement for a person called e.g. O'Neil. The cure is simple: Put a line such as the following before you construct any SQL: $priimek = AddSlashes( $priimek ); > AnD. Jan

« previous php.general (#58) next »