Re: Escaping special characters in sql
| From: | William Lovaton | Date: | Thu, 11 Jul 2002 13:23:32 +0000 |
| Subject: | Re: Escaping special characters in sql | ||
| References: | 1 2 | Groups: | php.pear.general |
| Request: | Send a blank email to pear-general+get-1849@lists.php.net to get a copy of this message | ||
El mié, 10-07-2002 a las 20:44, Bob Bell escribió:
> On Wed, Jul 10, 2002 at 06:28:29PM -0500, William Lovaton <walovaton@yahoo.com.mx> wrote:
> > I have a problem escaping special characters in the SQL's sentences... I
> > inserted the next text in a database field: Giovanni's.
> >
> > In Mysql I got this: Giovanni\\\'s
> > In Oracle I got this: Giovanni\'s
>
> Are you using DB::quote()?
Nop, I'm not using that method, I just did this:
$sql = "insert into clientes
(login,password,nombres,apellidos,edad,telefono,direccion,idioma) values
(?,?,?,?,?,?,?,?)";
$sentencia = $db->prepare($sql);
$datos =
Array($txtLogin,$txtPassword,$txtNombres,$txtApellidos,$txtEdad,$txtTelefono,$txtDireccion,$cmbIdioma);
$insert = $db->execute($sentencia, $datos);
if (DB::isError($insert)) {
// Handle the error
}
else {
// Every thing seems to be OK
}
In this case $txtNombres = "Giovanni's".
I was checking the source code in DB class and it doesn't have any
method called quote();
I have a method quote() and quoteString() in DB_common class.
Is there a mistake in the documentation? or is my version of PEAR too
old??
I'm using the PEAR version that comes with PHP 4.1.2 on a Linux system
Anyway, I tried with the quoteString() method and I got the next result:
In Mysql: Giovanni\'s
In Oracle: Giovanni\'s
Any idea about how to solve this??
TIA
William
_________________________________________________________
Do You Yahoo!?
Get your free @yahoo.com address at http://mail.yahoo.com