RE: [PHP-WIN] How to correctly handle textual form inputs for SQL inserts/updates?

From: Date: Tue, 16 Jan 2001 16:41:24 +0000
Subject: RE: [PHP-WIN] How to correctly handle textual form inputs for SQL inserts/updates?
Groups: php.windows 
Request: Send a blank email to php-windows+get-5049@lists.php.net to get a copy of this message
Hi, I ended up using the setting the use_sybase_quotes in the php.ini file to handle this problem. -Flint -----Original Message----- From: Romulo Roberto Pereira [mailto:php@diffdev.com] Sent: Tuesday, January 16, 2001 12:32 AM To: php-windows@lists.php.net; Mike Flynn Subject: Re: [PHP-WIN] How to correctly handle textual form inputs for SQL inserts/updates? > For instance, if a form has <input type="text"> and/or <textarea> inputs, > how do you treat the results of those inputs to safely insert them into the > database, to correct for 'single quotes, "double quotes, \slashes, etc etc > etc. I had the same problem - what I did to solve was use addslashes() in the string before I send them to the database. This is working great for all the user inputs - until now... > So, in other words, I have a form with some inputs, named perhaps text1 and text2. > Then, when they submit the form, I want to insert or update that entry with those values, like.. > UPDATE tblStuff SET txtText1='".urlencode($text1)."', > txtText2='".urlencode($text2)."'"; > or something like that.. UPDATE tblStuff SET txtText1='".addslashes($text1)."', txtText2='".addslashes($text2)."'"; What do you think? Rom -- PHP Windows Mailing List (http://www.php.net/) To unsubscribe, e-mail: php-windows-unsubscribe@lists.php.net For additional commands, e-mail: php-windows-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.windows (#5049) next »