RE: [PHP] SQL syntax error in PHP script. dunno what's wrong

From: Date: Wed, 01 Aug 2001 16:53:06 +0000
Subject: RE: [PHP] SQL syntax error in PHP script. dunno what's wrong
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-60705@lists.php.net to get a copy of this message
*always always always* quote everything in SQL statements. you run the risk of letting people insert arbitrary SQL statements into your script if you dont quote values. if you're using MySQL, try mysql_escape_string http://php.net/manual/en/function.mysql-escape-string.php or you could roll your own with relative ease: function db_quote($value) { return "'". preg_replace("/'/", "''", $value) ."'" } > -----Original Message----- > From: Matt Greer [mailto:mgreer@fieldmuseum.org] > Sent: Wednesday, August 01, 2001 12:45 PM > To: php-general@lists.php.net > Subject: Re: [PHP] SQL syntax error in PHP script. dunno what's wrong > > > on 8/1/01 11:35 AM, Chris Worth at caw@bcc.louisville.edu wrote: > > > > > > > hey gang. > > > > here is my sql statement from my php script. > > > > $sql = "UPDATE TABLE seminar SET > > title=$title,speaker=$speaker,event_date=$tdate,time=$time,bldg=$building > > ,rm=$room WHERE id=$id"; > > > > strings in a mysql query need to be quoted. So change it to > > $sql = "UPDATE TABLE seminar SET > title='$title',speaker='$speaker',..."; > > Matt > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net >

« previous php.general (#60705) next »