Jump to content

[SOLVED] Sending a ' in query causes an error


burntheblobs

Recommended Posts

Thank you for the link. I didn't even think about that kind of security flaw. I now have this in my code and for some reason it is bad sql syntax and it can't even execute the query now no matter what.

 

'sprintf('%s',mysqli_real_escape_string($_POST[Comment]))'

		$query = "INSERT INTO post (Id,comment,first,second,third,posterIp,postDate)
							VALUES ('".mysqli_insert_id($cxn)."','sprintf('%s',mysqli_real_escape_string($_POST[Comment]))','$_POST[firstRating]',
									'$_POST[secondRating]','$_POST[thirdRating]','".getIp()."',
									'".date("Y/m/d")."')";

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.