note 5296 deleted from ref.strings by aidan

From: Date: Tue, 28 Sep 2004 12:12:54 +0000
Subject: note 5296 deleted from ref.strings by aidan
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-77501@lists.php.net to get a copy of this message
Note Submitter: mfawcett at tir dot com ---- For a MySQL problem (where a user might put quotes in a text field from a form) use addslashes() to escape all quotes (single and double). For example: // Assuming 'textstuff' is from a form $mytextstuff = addslashes($textstuff); $sql = "insert into MyTable set MyField='$mytextstuff'"; Also if you are working with html forms and/or text fields from databases a lot you'll probably want to read up on commands like htmlspecialchars() as well (a field like "foo<bar>" might not throw MySQL off but it won't display correctly in an html page).

« previous php.notes (#77501) next »