RE: [PHP] inserting free-form text with quotes to mysql
| From: | Don Read | Date: | Fri, 20 Jul 2001 20:30:32 +0000 |
| Subject: | RE: [PHP] inserting free-form text with quotes to mysql | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-58971@lists.php.net to get a copy of this message | ||
On 20-Jul-2001 garman wrote:
> I'm creating a specialized "suggestion box" type of web application in PHP.
> I'm using MySQL for data storage.
>
> Whenever I try to submit text that contains a double quote character ("),
> the
> submission gets truncated at the first occurance of a double quote and
> beyond.
> Single quotes don't seem to be problematic.
>
> So if the user inputted the following text:
>
> hello " my suggestion for deals with improving the...
>
> then only "hello" would get put in the database, and everything from the
> double quote to the end of the input would be truncated.
>
> I've tried addslashes() and removeslashes() before the submit, but that
> doesn't seem to help.
>
You didn't post any code, but I'll bet you're double quoting your query.
$qry="INSERT INTO da_table (foo) VALUES ('$bar')";
try :
$qry=sprintf('INSERT INTO da_table (foo) VALUES ('%s')', $bar);
on the Select / display:
echo nl2br(htmlspecialchars(stripslashes($row->foo)));
also checkout 'set_magic_quotes_runtime()'
Regards,
--
Don Read dread@texas.net
-- It's always darkest before the dawn. So if you are going to
steal the neighbor's newspaper, that's the time to do it.