RE: [PHP-WIN] How to correctly handle textual form inputs for SQL inserts/updates?
| From: | Flint Doungchak | Date: | Tue, 16 Jan 2001 16:41:24 +0000 |
| Subject: | RE: [PHP-WIN] How to correctly handle textual form inputs for SQL inserts/updates? | ||
| Groups: | php.windows | ||
| Request: | Send a blank email to php-windows+get-5049@lists.php.net to get a copy of this message | ||
Hi,
I ended up using the setting the use_sybase_quotes in the php.ini file to
handle this problem.
-Flint
-----Original Message-----
From: Romulo Roberto Pereira [mailto:php@diffdev.com]
Sent: Tuesday, January 16, 2001 12:32 AM
To: php-windows@lists.php.net; Mike Flynn
Subject: Re: [PHP-WIN] How to correctly handle textual form inputs for
SQL inserts/updates?
> For instance, if a form has <input type="text"> and/or <textarea> inputs,
> how do you treat the results of those inputs to safely insert them into
the
> database, to correct for 'single quotes, "double quotes, \slashes, etc etc
> etc.
I had the same problem - what I did to solve was use addslashes() in the
string before I send them to the database. This is working great for all the
user inputs - until now...
> So, in other words, I have a form with some inputs, named perhaps text1
and
text2.
> Then, when they submit the form, I want to insert or update that entry
with
those values, like..
> UPDATE tblStuff SET txtText1='".urlencode($text1)."',
> txtText2='".urlencode($text2)."'";
> or something like that..
UPDATE tblStuff SET txtText1='".addslashes($text1)."',
txtText2='".addslashes($text2)."'";
What do you think?
Rom
--
PHP Windows Mailing List (http://www.php.net/)
To unsubscribe, e-mail: php-windows-unsubscribe@lists.php.net
For additional commands, e-mail: php-windows-help@lists.php.net
To contact the list administrators, e-mail: php-list-admin@lists.php.net