note 18888 deleted from function.mysql-escape-string by aidan
| From: | aidan@php.net | Date: | Wed, 11 Aug 2004 14:08:30 +0000 |
| Subject: | note 18888 deleted from function.mysql-escape-string by aidan | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-74456@lists.php.net to get a copy of this message | ||
Note Submitter:
----
if you use mysql_result(0,1)
and 0,1 has a quote in the text it won't escape the ' if you put it directly into a
sql query
example: wrong
$sql = "INSERT INTO tblsubdocuments (text) VALUES ('".
mysql_result($subdocuments,$a,1))."' )";
example: good
$sql = "INSERT INTO tblsubdocuments (text) VALUES ('".
mysql_escape_string(mysql_result($subdocuments,$a,1))."')";
if you dont do this your F#*&%%%ked