Quote handling problem in SQL statement
Brought to you by:
mplante
The code to insert a new entry, found in
master.functions.inc.php, contains:
$result_ecf = mysql_query("INSERT INTO Person
(LastName,
FirstName,
SubGroup)
VALUES
('$LastName',
'$FirstName',
'$SubGroup')");
If $LastName, $FirstName, or $SubGroup contains a
single quote then the result is invalid SQL. In my
case the SubGroup was "Joe's Family". I didn't check
the rest of the code for other instances of this
problem.