Menu ▾ ▴

#3 Quote handling problem in SQL statement

open
nobody
None
5
2001-05-15
2001-05-15
Anonymous
No

The code to insert a new entry, found in
master.functions.inc.php, contains:

$result_ecf = mysql_query("INSERT INTO Person
(LastName,
FirstName,
SubGroup)
VALUES
('$LastName',
'$FirstName',
'$SubGroup')");

If $LastName, $FirstName, or $SubGroup contains a
single quote then the result is invalid SQL. In my
case the SubGroup was "Joe's Family". I didn't check
the rest of the code for other instances of this
problem.

Discussion


Log in to post a comment.