note 31175 deleted from function.addslashes by philip
| From: | philip@php.net | Date: | Tue, 20 Jul 2004 17:14:23 +0000 |
| Subject: | note 31175 deleted from function.addslashes by philip | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-73708@lists.php.net to get a copy of this message | ||
Note Submitter: mbone@matthewbone.com
----
I got the idea from an earlier post however it didn't work so I modified it and am posting to
help anyone who whats to insert form fields to a microsoft sql database or microsoft access file and
doesn't want to worry about magic quotes. On the query string BEFORE you insert or update any
data that's be submitted from a form add this simple function:
$variable_name = ereg_replace("'", "`",$variable_name);
(the to be replaced field is a " ' " only without the spaces, it's hard to tell
when looking at it)
you'll have add this for any form field that might contain an ' . This will change all
' to an ` which isn't an apostrophe but is a character that is very RARELY used.
when you go to select the information and print it out simply change it back like this
$variable_name = ereg_replace("`", "'",$variable_name);
for each field that could have an ` in it somewhere. Sometimes I confuse myself when I write so if
you're confused feel free to email me.