note 5296 deleted from ref.strings by aidan
| From: | aidan@php.net | Date: | Tue, 28 Sep 2004 12:12:54 +0000 |
| Subject: | note 5296 deleted from ref.strings by aidan | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-77501@lists.php.net to get a copy of this message | ||
Note Submitter: mfawcett at tir dot com
----
For a MySQL problem (where a user might put quotes in a text field from a form) use addslashes() to
escape all quotes (single and double). For example:
// Assuming 'textstuff' is from a form
$mytextstuff = addslashes($textstuff);
$sql = "insert into MyTable set MyField='$mytextstuff'";
Also if you are working with html forms and/or text fields from databases a lot you'll probably
want to read up on commands like htmlspecialchars() as well (a field like "foo<bar>"
might not throw MySQL off but it won't display correctly in an html page).