note 18888 added to function.mysql-escape-string
| From: | php-general at lists dot php dot net | Date: | Fri, 08 Feb 2002 14:38:09 +0000 |
| Subject: | note 18888 added to function.mysql-escape-string | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-26384@lists.php.net to get a copy of this message | ||
if you use msql_result(0,1)
and 0,1 has a quote in the text it won't escape the ' if you put it directly into a
sql query
example: wrong
$sql = "INSERT INTO tblsubdocuments (text) VALUES ('".
mysql_result($subdocuments,$a,1))."' )";
example: good
$sql = "INSERT INTO tblsubdocuments (text) VALUES ('".
mysql_escape_string(mysql_result($subdocuments,$a,1))."')";
if you dont do this your F#*&%%%ked
--
http://www.php.net/manual/en/function.mysql-escape-string.php
http://master.php.net/manage/user-notes.php?action=edit+18888
http://master.php.net/manage/user-notes.php?action=delete+18888
http://master.php.net/manage/user-notes.php?action=reject+18888