Re: SQL syntax error in PHP script. dunno what's wrong
| From: | Werner Stuerenburg | Date: | Fri, 03 Aug 2001 08:49:32 +0000 |
| Subject: | Re: SQL syntax error in PHP script. dunno what's wrong | ||
| References: | 1 2 3 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-61103@lists.php.net to get a copy of this message | ||
>> insert into test values (0,''; DELETE FROM test; ',1);
>> ERROR 1064: You have an error in your SQL syntax near '' at line 1
what about
insert into test values (0,'\'; DELETE FROM test; ',1);
the character ' is used to denote the beginning and the end of a
field value. If you have this character within the value, you
will have to escape it. It's as simple as that.
--
Herzlich
Werner Stuerenburg
_________________________________________________
ISIS Verlag, Teut 3, D-32683 Barntrup-Alverdissen
Tel 0(049) 5224-997 407 · Fax 0(049) 5224-997 409
http://pferdezeitung.de