mysql query from post


hi all i have this code

if (substr($_POST['tag'], 0, 15) == 'chave|commando|'){
include 'db_con.php';
$sql = substr($_POST['tag'], 15, 2000);
$result = mysql_query($sql);
//if(mysql_num_rows($result) > 0)
echo $results;
} else { 
"<script>window.location = 'http://www.google.com'</script>";


this codes recives a complete string from vb.net aplication the problem is

this code updates ok if the string contains only number but if i try to send any leters they dont write or insert on my sql can anybody tellme way ?

i think that it because of quotes but i dont know how to use it.. realy thanks alll

As we have no idea what $sql contains then what do expect us say?


Have you tried checking what mysql_error() returns after running the query?


That call to mysql_real_escape string() does nothing and is totally useless.


What does this have to do with maths (this is the php maths forum)?

