douzhaolu4839 2012-10-05 14:15
浏览 65
已采纳

如何在JOOMLA 2.5中的数据库中插入数据时转义引号

I am trying to insert data in database(mysql) but not successful when i am trying to add data with single or double quotes.Its working fine otherwise(without Quote). I know we have to use mysql_real_escape_string in such situations.But i am using joomla framework where this function is not working.

My code is below:

function insert($table, $array) {
$db = JFactory::getDBO();
 $query = "INSERT INTO ".$table;
  $fis = array();
  $vas = array();
  foreach($array as $field=>$val) {

 if(is_array($val)){
 $x= implode(",",$val);
 }
 else
 {
 $x=$val;
 }

   $fis[] = "`$field`";//you must verify keys of array outside of function;
                         //unknown keys will cause mysql errors;
                         //there is also sql injection risc;
    $vas[] = "'".$x."'";
  }
$query .= " (".implode(", ", $fis).") VALUES (".implode(", ", $vas).")";
$db->setQuery($query);
$db->query();
}
insert('#__storage_companies',JRequest::get( 'post' ));

Please tell me how to get rid of this.

  • 写回答

2条回答 默认 最新

  • dongxi1320 2012-10-05 15:28
    关注

    See JDatabaseDriver::quote. Used like $db->quote($value). Also to quote field names, use $db->quoteName($value).

    Take a look at Preparing the query from the Joomla wiki.

    You code should be like:

    $fis[] = $db->nameQuote($field);
    $vas[] = $db->quote($x);
    
    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论
查看更多回答(1条)

报告相同问题?

悬赏问题

  • ¥15 c语言怎么用printf(“\b \b”)与getch()实现黑框里写入与删除?
  • ¥20 怎么用dlib库的算法识别小麦病虫害
  • ¥15 华为ensp模拟器中S5700交换机在配置过程中老是反复重启
  • ¥15 java写代码遇到问题,求帮助
  • ¥15 uniapp uview http 如何实现统一的请求异常信息提示?
  • ¥15 有了解d3和topogram.js库的吗?有偿请教
  • ¥100 任意维数的K均值聚类
  • ¥15 stamps做sbas-insar,时序沉降图怎么画
  • ¥15 买了个传感器,根据商家发的代码和步骤使用但是代码报错了不会改,有没有人可以看看
  • ¥15 关于#Java#的问题,如何解决?