Re: Apostrophes/SQL Statements
| From: | Jan Dvorak | Date: | Mon, 15 May 2000 10:09:12 +0000 |
| Subject: | Re: Apostrophes/SQL Statements | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-58@lists.php.net to get a copy of this message | ||
Andrej Trobentar wrote:
>
> Emile Axelrad wrote:
>
> > I'm getting problems with my SQL Statements where the data has apostrophes
> > [single quotes]. It messes up the insertion procedure - what should I do?
> > How do I get rid of the single quotes from a string?
> >
> > Cheers for your help! I know its an easy question but I can't find the
> > proper thing to do on it...
> >
> > - Emile Axelrad
>
> Maybe this example will help you :
> print '<PARAM NAME="text1" VALUE="' . $ime .
> '">';
>
> or this one
> $stmt = OCIParse($c,"select * from imenik where PRIIMEK='$priimek'");
Wuups!!
But this will produce an invalid SQL statement
for a person called e.g. O'Neil.
The cure is simple:
Put a line such as the following before you construct any SQL:
$priimek = AddSlashes( $priimek );
> AnD.
Jan