Jump to content

mysql_real_escape_string and update


garydt

Recommended Posts

Is there anyway to way to use mysql_real_escape_string when updating a record? i've tried-

$updateSQL = sprintf("UPDATE images SET imageName='$smallimage', bigimagename='$smallpics', bigcaption='" . mysql_real_escape_string(%s) . "' WHERE usnm='$user'", 
      GetSQLValueString($_POST['textfield'], "text"));

and i get-

 

Parse error: parse error, unexpected '%', expecting ')' in C:\Program Files\xampp\htdocs\epeople\editphoto.php on line 173

 

 

Also I want to check if people try and type in url's into the guestbook. How do i do that?  Is it with the 'ereg' command?

 

Thanks alot

Link to comment
https://forums.phpfreaks.com/topic/57697-mysql_real_escape_string-and-update/
Share on other sites

Is there anyway to way to use mysql_real_escape_string when updating a record?

 

you can do something like this...

 

$failed = mysqli_real_escape_string($mysqli,trim($_POST['failed_logins']));

 

//update failed logins

$sql = "UPDATE employees SET failed_logins = '".$failed."' WHERE username = '".$_SESSION['user']."' LIMIT 1";

mysqli_query($mysqli, $sql);

 

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.