dsjq6977 2018-05-30 09:10
浏览 78
已采纳

撇号[']不保存在数据库中

Values don't save in database when I use : apostrophe [ ' ]

I changed database collation to "utf8_general_ci" & column type to BLOB.

addslashes :

<td <?php if($userdepart==0 ) { ?>
    contenteditable="true"
    onBlur="saveToDatabase(this,'name','<?php echo addslashes($orderrecords[$k]["id"]); ?>')"
    <?php } ?>>
    <?php echo substr(addslashes($orderrecords[$k]["name"]),0,75); ?>
</td>

Also I tried mysqli_real_escape_string

<td <?php if($userdepart==0 ){?>
    contenteditable="true"
    onBlur="saveToDatabase(this,'name','<?php echo addslashes(mysqli_real_escape_string($mysqli,$orderrecords[$k]["id"])); ?>')"
    <?php }?>>
    <?php echo addslashes(mysqli_real_escape_string($mysqli,substr($orderrecords[$k]["name"],0,975))); ?>
</td> 

Right now I really can't use prepared statements and parameterized queries, as this is used by only company users. Please help me with a work around....

update

function saveToDatabase(editableObj,column,id) {

    if(column=="image_ready" || column=="ready_to_print" || column=="ready_to_packaging" || column=="ready_to_dispatch"){cvalue=editableObj;}else{var cvalue=$(editableObj).text();}

      $.ajax({
        url: "editOrder.php",
        type: "POST",
        data:'column='+column+'&editval='+cvalue+'&id='+id,
        success: function(data){
          $(editableObj).css("background","#dddddd");
          if(column=="image_ready" || column=="ready_to_print" || column=="ready_to_packaging" || column=="ready_to_dispatch"){location.reload();}
        }
      });

editOrder.php

$sql = "UPDATE do_order set " . $_POST["column"] . " = '".$_POST["editval"]."' WHERE  id=".$_POST["id"];
  • 写回答

1条回答 默认 最新

  • dongshipang8094 2018-05-30 09:16
    关注

    use prepared statements:

    $stmt = $conn->prepare("INSERT INTO MyGuests (firstname, lastname, email) VALUES (?, ?, ?)");
    $stmt->bind_param("sss", $firstname, $lastname, $email);
    $firstname = "John";
    $lastname = "D'''oe";
    $email = "john@example.com";
    $stmt->execute();
    
    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 使用ue5插件narrative时如何切换关卡也保存叙事任务记录
  • ¥20 软件测试决策法疑问求解答
  • ¥15 win11 23H2删除推荐的项目,支持注册表等
  • ¥15 matlab 用yalmip搭建模型,cplex求解,线性化处理的方法
  • ¥15 qt6.6.3 基于百度云的语音识别 不会改
  • ¥15 关于#目标检测#的问题:大概就是类似后台自动检测某下架商品的库存,在他监测到该商品上架并且可以购买的瞬间点击立即购买下单
  • ¥15 神经网络怎么把隐含层变量融合到损失函数中?
  • ¥15 lingo18勾选global solver求解使用的算法
  • ¥15 全部备份安卓app数据包括密码,可以复制到另一手机上运行
  • ¥20 测距传感器数据手册i2c