RE: [PHP] SQL syntax error in PHP script. dunno what's wrong
| From: | scott [gts] | Date: | Wed, 01 Aug 2001 16:53:06 +0000 |
| Subject: | RE: [PHP] SQL syntax error in PHP script. dunno what's wrong | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-60705@lists.php.net to get a copy of this message | ||
*always always always* quote everything in SQL statements.
you run the risk of letting people insert arbitrary
SQL statements into your script if you dont quote values.
if you're using MySQL, try mysql_escape_string
http://php.net/manual/en/function.mysql-escape-string.php
or you could roll your own with relative ease:
function db_quote($value) {
return "'". preg_replace("/'/", "''", $value)
."'"
}
> -----Original Message-----
> From: Matt Greer [mailto:mgreer@fieldmuseum.org]
> Sent: Wednesday, August 01, 2001 12:45 PM
> To: php-general@lists.php.net
> Subject: Re: [PHP] SQL syntax error in PHP script. dunno what's wrong
>
>
> on 8/1/01 11:35 AM, Chris Worth at caw@bcc.louisville.edu wrote:
>
> >
> >
> > hey gang.
> >
> > here is my sql statement from my php script.
> >
> > $sql = "UPDATE TABLE seminar SET
> > title=$title,speaker=$speaker,event_date=$tdate,time=$time,bldg=$building
> > ,rm=$room WHERE id=$id";
> >
>
> strings in a mysql query need to be quoted. So change it to
>
> $sql = "UPDATE TABLE seminar SET
> title='$title',speaker='$speaker',...";
>
> Matt
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>