note 62127 added to function.addslashes

From: Date: Mon, 20 Feb 2006 22:09:27 +0000
Subject: note 62127 added to function.addslashes
Groups: php.notes 
Request: Send a blank email to php-notes+get-104088@lists.php.net to get a copy of this message
Don't waste your time on this like I did: If you are comparing strings in a query on mySQL and the stored column has been escaped by addslashes you might have some problems. It was not simply good enough to addslashes once to the comparison variable but twice; MySql does not account for the escaped characters. $temp = 'Mike's Notes'; t1 * textColumn ************** r1 * Quick Notes r2 * Mike\\'s Notes $sqlQuery = "select * from t1 where textColumn = '".addslashes($temp)."'; //returns no rows! $sqlQuery = "select * from t1 where textColumn = '".addslashes(addslashes($temp))."'; //returns 1 row! ---- Server IP: 216.194.113.175 Probable Submitter: 206.196.145.161 ---- Manual Page -- http://www.php.net/manual/en/function.addslashes.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+62127 Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+62127&report=yes&reason=added+to+the+manual Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+62127&report=yes&reason=bad+code Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+62127&report=yes&reason=spam Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+62127&report=yes&reason=useless Delete: non-english -- http://master.php.net/manage/user-notes.php?action=delete+62127&report=yes&reason=non-english Delete: already in docs -- http://master.php.net/manage/user-notes.php?action=delete+62127&report=yes&reason=already+in+docs Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+62127&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+62127&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#104088) next »