destrugter
03-30-2008, 08:05 AM
Ok, this has to do with some code i received help on...its listed below.
<?php
$con = mysql_connect("mysql","cheese","pizza");
if (!$con)
{
die('Could not connect: ' . mysql_error());
}mysql_select_db("cheese", $con);$sql=$sql='INSERT INTO `SkillGuides` (`author`, `title`, `skill`, `p&f`, `guide`, `credit`)
VALUES
(\''.mysql_escape_string($_COOKIE["username"]).'\',\''.mysql_escape_string($_POST['title']).'\',\''.mysql_escape_string($_POST['skill']).'\',\''.mysql_escape_string($_POST['p&f']).'\',\''.mysql_escape_string($_POST['guide']).'\',\''.mysql_escape_string($_POST['credit']).'\')';
if (!mysql_query($sql,$con))
{
die('Error: ' . mysql_error());
}
mysql_close($con);
}
?>
Ok, now when someone puts a ' for something like "Cook's assistant" it will be diplayed "Cook/s assistant"
How can i fix this?
<?php
$con = mysql_connect("mysql","cheese","pizza");
if (!$con)
{
die('Could not connect: ' . mysql_error());
}mysql_select_db("cheese", $con);$sql=$sql='INSERT INTO `SkillGuides` (`author`, `title`, `skill`, `p&f`, `guide`, `credit`)
VALUES
(\''.mysql_escape_string($_COOKIE["username"]).'\',\''.mysql_escape_string($_POST['title']).'\',\''.mysql_escape_string($_POST['skill']).'\',\''.mysql_escape_string($_POST['p&f']).'\',\''.mysql_escape_string($_POST['guide']).'\',\''.mysql_escape_string($_POST['credit']).'\')';
if (!mysql_query($sql,$con))
{
die('Error: ' . mysql_error());
}
mysql_close($con);
}
?>
Ok, now when someone puts a ' for something like "Cook's assistant" it will be diplayed "Cook/s assistant"
How can i fix this?