I have weird problem while inserting the string in my custom table.]
I have a form in which one description field available. When a user fills that description field with some string containing apostrophe s eg. (Children's playground). Blank Value stored in database and sometime insert query is not fire.
$description = $_POST['description'];
$sql = "INSERT INTO sample_table (description_field) VALUES($description)";
$stmt = $modx->prepare($sql);
$stmt->execute();
Everything is fine if there is no apostrophe s(" ' ") in the string. Don't know why not allow this symbol.
Arkalp.com
-
☆ A M B ☆
- 3,141 Posts
That is not the right way to insert data.. at all. That's a huge security risk. The reason it's failing when you have an apostrophe is because that is breaking the query, opening it up to SQL injection attacks.
At the very least you should be properly escaping the $description before inserting it into the query. You can use $modx->quote($description) for that. So something like this:
$description = $modx->quote($_POST['description']);
$sql = "INSERT INTO sample_table (description_field) VALUES($description)";
$stmt = $modx->prepare($sql);
$stmt->execute();
It would be even better - but a steeper learning curve and more work getting set up - to learn about using xPDO for data manipulation. This should be a good starting point:
http://rtfm.modx.com/revolution/2.x/case-studies-and-tutorials/using-custom-database-tables-in-your-3rd-party-components
Thanks For your reply. It works fine.
Arkalp.com