douchang6770 2012-03-20 03:48
浏览 122
已采纳

使用单引号将数据添加到php mysql中

This is my code:

$q=mysql_query("SELECT * FROM `table1` WHERE name like '%$searchText%'");

      while($e=mysql_fetch_assoc($q))

              //$output[]=$e;
              //echo $e['NAME'];
              {
              $name = $e['NAME'];
              $brand = $e['BRAND'];
              $category = $e['CATEGORY'];
              $query = "INSERT INTO table2 (brand, name, category) VALUES ('$brand', '$name', '$category')";
              $result = mysql_query($query) or die("Unable to insert because : " . mysql_error()); 
              }

Since in "BRAND", there may be some data like "First's Choice".
In this case, I cannot insert to database due to error.
How can I insert data that contain single quotes? Thx

  • 写回答

6条回答 默认 最新

  • dongnai2804 2012-03-20 03:51
    关注

    you need to use mysql_real_escape_string on the value, which you should be doing anyway. That should properly escape your value for insertion.

    $name = mysql_real_escape_string($e['NAME']);
    $brand = mysql_real_escape_string($e['BRAND']);
    $category = mysql_real_escape_string($e['CATEGORY']);
    $query = "INSERT INTO table2 (brand, name, category) VALUES ('$brand', '$name', '$category')";
    
    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论
查看更多回答(5条)

报告相同问题?

悬赏问题

  • ¥15 怎样才能让鼠标沿着线条的中心线轨迹移动
  • ¥60 用visual studio编写程序,利用间接平差求解水准网
  • ¥15 Llama如何调用shell或者Python
  • ¥20 谁能帮我挨个解读这个php语言编的代码什么意思?
  • ¥15 win10权限管理,限制普通用户使用删除功能
  • ¥15 minnio内存占用过大,内存没被回收(Windows环境)
  • ¥65 抖音咸鱼付款链接转码支付宝
  • ¥15 ubuntu22.04上安装ursim-3.15.8.106339遇到的问题
  • ¥15 blast算法(相关搜索:数据库)
  • ¥15 请问有人会紧聚焦相关的matlab知识嘛?