RE: [PHP] SQL syntax error in PHP script. dunno what's wrong

From: Date: Wed, 01 Aug 2001 17:02:56 +0000
Subject: RE: [PHP] SQL syntax error in PHP script. dunno what's wrong
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-60712@lists.php.net to get a copy of this message
no offense to you sam, but please dont ever simply place single quotes around values. you have to escape the values *themselves*. what if someone submitted the form field title as: $title = "'; DELETE FROM seminar; " if you didn't escape the single quotes in there, it would get interpreted as a valid DELETE statement and your seminar table would get wiped. however, if you escaped $title, you'd end up setting title to "\'; DELETE FROM SEMINAR; " (rather than have the contents of $title interpreted as SQL commands) > -----Original Message----- > From: Sam Masiello [mailto:smasiello@synacor.com] > Subject: RE: [PHP] SQL syntax error in PHP script. dunno what's wrong > > > You will need to put single quotes around your variables in your SQL > statement. Like this: > > $sql = "UPDATE TABLE seminar SET > > title='$title',speaker='$speaker',event_date='$tdate',time='$time',bldg='$bu > ilding' > ,rm='$room' WHERE id='$id'"; > > Without the quotes, SQL doesn't know that Something Amazing is supposed to > go together in the same string. > > HTH

« previous php.general (#60712) next »