note 37765 deleted from function.addslashes by didou
| From: | didou@php.net | Date: | Wed, 26 Nov 2003 08:43:58 +0000 |
| Subject: | note 37765 deleted from function.addslashes by didou | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-60992@lists.php.net to get a copy of this message | ||
Note Submitter: wayne dean
----
Running apache/php under win2k, with magic_quotes_gpc on, querying MS Sql-server via ODBC, I needed
to escape single quotes (e.g. O'Neal).
addslashes() was not the solution. Instead, I wrote the following function, which uses a single
quote to escape the single quote, as per the ansi standard sql:
function sani($txt){
if(stristr($txt, "'")){
$txt=ereg_replace("'","''", $txt);
return stripslashes($txt);
}
}
then I enter queries like:
"select column from table where column like '".sani($find)."%'"