Fw: [PHP] Inserting variables (Revised)

From: Date: Tue, 09 Oct 2001 14:45:07 +0000
Subject: Fw: [PHP] Inserting variables (Revised)
Groups: php.general 
Request: Send a blank email to php-general+get-70494@lists.php.net to get a copy of this message
> >From a form, I pass the variables "$q1" and $q2" > I also pass the following ATTEMPTS on an variable that is an SQL statement: > > INSERT INTO mytable ('$q1', '$q2', '2001-10-09') > or > INSERT INTO mytable ("$q1", "$q2", "2001-10-09") > > I have tried executing the SQL statement like this: > > $query = $sqlstatement; > $result = MYSQL_QUERY($query); > > as well as > > $query = "$sqlstatement"; > $result = MYSQL_QUERY($query); > > > No matter what I get the values literally "q1" and "q2" sent to the table > and NOT their respective values Cause when You pass something from a form thai it is a string (no matter if there's $q1 entered into it and that You have $q1 declared) and it's not interpreted, so the querry contains '$q1', '$q2' strings, not the variables values. The solution for You was allready presented: do not pass the querry as You did, but like this: <INPUT TYPE="whatever" NAME="querry" VALUE="INSERT INTO mytable ('replacer_1', 'replacer_2', '2001-10-09')"> <INPUT TYPE="whatever" NAME="q1" VALUE="some_value_1"> <INPUT TYPE="whatever" NAME="q2" VALUE="some_value_2"> and handle it: $querry = ereg_replace( "replacer_1", $q1, $querry ); $querry = ereg_replace( "replacer_2", $q2, $querry ); $result = MYSQL_QUERY($query); Kamil 'Hilarion' Nowicki

« previous php.general (#70494) next »