note 31175 added to function.addslashes
| From: | mbone at matthewbone dot com | Date: | Fri, 11 Apr 2003 23:41:33 +0000 |
| Subject: | note 31175 added to function.addslashes | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-46530@lists.php.net to get a copy of this message | ||
I got the idea from an earlier post however it didn't work so I modified it and am posting to
help anyone who whats to insert form fields to a microsoft sql database or microsoft access file and
doesn't want to worry about magic quotes. On the query string BEFORE you insert or update any
data that's be submitted from a form add this simple function:
$variable_name = ereg_replace("'", "`",$variable_name);
(the to be replaced field is a " ' " only without the spaces, it's hard to tell
when looking at it)
you'll have add this for any form field that might contain an ' . This will change all
' to an ` which isn't an apostrophe but is a character that is very RARELY used.
when you go to select the information and print it out simply change it back like this
$variable_name = ereg_replace("`", "'",$variable_name);
for each field that could have an ` in it somewhere. Sometimes I confuse myself when I write so if
you're confused feel free to email me.
--
http://www.php.net/manual/en/function.addslashes.php
http://master.php.net/manage/user-notes.php?action=edit+31175
http://master.php.net/manage/user-notes.php?action=delete+31175
http://master.php.net/manage/user-notes.php?action=reject+31175