RE: [PHP] Why doesn't this simple query work?
| From: | Lawrence dot Sheed at dfait-maeci dot gc dot ca | Date: | Thu, 26 Jul 2001 01:54:49 +0000 |
| Subject: | RE: [PHP] Why doesn't this simple query work? | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-59662@lists.php.net to get a copy of this message | ||
how about
$location = addslashes($location);
$query = "select shoodID from shoots where location = '$location'";
or
$query = "select shoodID from shoots where location = '".
addslashes($location) ."'";
Both are \'clean\' :)
-----Original Message-----
From: Moriyoshi Koizumi [mailto:readjust@deneb.freemail.ne.jp]
Sent: July 26, 2001 4:59 AM
To: php-general@lists.php.net
Subject: Re: [PHP] Why doesn't this simple query work?
IMHO
$query = "SELECT shoodID FROM shoots WHERE location=\"$location\"";
and even
$query = "SELECT shoodID FROM shoots WHERE location='$location'";
sometimes cause SQL Syntax Error,
because the variable $location may contain quote characters (')(")...
since i experienced the same thing i've been doing like this...
(the reason is just that i did with 2 byte japanese characters?)
--------------------------------------------------------
$query = sprintf(
'SELECT shootID FROM shoots WHERE location="%s"',
AddSlashes( $location )
);
--------------------------------------------------------
going well, but is this code too ugry?
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
For additional commands, e-mail: php-general-help@lists.php.net
To contact the list administrators, e-mail: php-list-admin@lists.php.net