Fw: [PHP] Inserting variables (Revised)
| From: | Kamil Nowicki | Date: | Tue, 09 Oct 2001 14:45:07 +0000 |
| Subject: | Fw: [PHP] Inserting variables (Revised) | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-70494@lists.php.net to get a copy of this message | ||
> >From a form, I pass the variables "$q1" and $q2"
> I also pass the following ATTEMPTS on an variable that is an SQL
statement:
>
> INSERT INTO mytable ('$q1', '$q2', '2001-10-09')
> or
> INSERT INTO mytable ("$q1", "$q2", "2001-10-09")
>
> I have tried executing the SQL statement like this:
>
> $query = $sqlstatement;
> $result = MYSQL_QUERY($query);
>
> as well as
>
> $query = "$sqlstatement";
> $result = MYSQL_QUERY($query);
>
>
> No matter what I get the values literally "q1" and "q2" sent to the table
> and NOT their respective values
Cause when You pass something from a form thai it is a string (no matter if
there's
$q1 entered into it and that You have $q1 declared) and it's not
interpreted, so
the querry contains '$q1', '$q2' strings, not the variables values.
The solution for You was allready presented:
do not pass the querry as You did, but like this:
<INPUT TYPE="whatever" NAME="querry" VALUE="INSERT INTO mytable
('replacer_1', 'replacer_2', '2001-10-09')">
<INPUT TYPE="whatever" NAME="q1" VALUE="some_value_1">
<INPUT TYPE="whatever" NAME="q2" VALUE="some_value_2">
and handle it:
$querry = ereg_replace( "replacer_1", $q1, $querry );
$querry = ereg_replace( "replacer_2", $q2, $querry );
$result = MYSQL_QUERY($query);
Kamil 'Hilarion' Nowicki