PHP Developers Network

A community of PHP developers offering assistance, advice, discussion, and friendship.
 
Loading
It is currently Tue Jul 07, 2020 11:42 pm

All times are UTC - 5 hours




Post new topic Reply to topic  [ 8 posts ] 
Author Message
PostPosted: Fri Feb 18, 2005 5:28 am 
Offline
Admin
User avatar

Joined: Wed Aug 13, 2003 7:02 am
Posts: 4522
Location: York, UK


Last edited by JayBird on Fri Jun 03, 2005 3:31 am, edited 1 time in total.

Top
 Profile  
 
 Post subject:
PostPosted: Thu Jun 02, 2005 4:23 am 
Offline
Admin
User avatar

Joined: Wed Aug 13, 2003 7:02 am
Posts: 4522
Location: York, UK
Updated the user guide :!:


Top
 Profile  
 
 Post subject:
PostPosted: Thu Jun 02, 2005 9:28 pm 
Offline
Site Admin
User avatar

Joined: Tue Dec 23, 2003 3:10 am
Posts: 11470
Location: Toronto
Looks good 8)


Top
 Profile  
 
 Post subject:
PostPosted: Fri Jun 03, 2005 4:52 am 
Offline
Jedi Mod
User avatar

Joined: Tue Dec 21, 2004 6:03 pm
Posts: 5263
Location: usrlab.com


Top
 Profile  
 
 Post subject:
PostPosted: Fri Jun 03, 2005 5:34 am 
Offline
Admin
User avatar

Joined: Wed Aug 13, 2003 7:02 am
Posts: 4522
Location: York, UK


Top
 Profile  
 
 Post subject:
PostPosted: Sun Jun 26, 2005 2:07 pm 
Offline
Forum Newbie

Joined: Fri Apr 08, 2005 7:17 am
Posts: 20
Use mysql_escape_string, that makes it impossible to insert any mysql code. Next when you display the values from the database use htmlspecialchars, which makes it impossible to insert any html code. (Like non-existing images, which src makes the user post a message on an openBB forum)


Top
 Profile  
 
 Post subject:
PostPosted: Sun Jun 26, 2005 2:28 pm 
Offline
Forum Commoner

Joined: Tue Mar 15, 2005 6:03 pm
Posts: 65


Top
 Profile  
 
 Post subject:
PostPosted: Sun Jun 26, 2005 3:46 pm 
Offline
DevNet Master

Joined: Tue Jan 20, 2004 12:11 am
Posts: 4897
Location: Leuven, Belgium
Here is the general thought.. Offcourse it becomes much more compliated...

Syntax: [ Download ] [ Hide ]
$columns = array();

$columns[] = array('name' => 'person_id', 'caption' => 'ID');

$columns[] = array('name' => 'surname', 'caption' => 'Surname');

...



$i = 0;

foreach($columns as $column)

{

  echo "{$column['caption']} : <input type='text' name='{$i}' />";

  ++$i;

}


And when it's posted back

Syntax: [ Download ] [ Hide ]
$sql1 = "INSERT INTO $table (";

$sql2 = ") VALUES (";

$i = 0;

foreach($columns as $column)

{

  $sql1 .= "{$column['name']}, ";

  $sql2 .= "'" . mysql_real_escape_string($_POST[$i], $db) . "', ";

  ++$i;

}

$sql1 = rtrim($sql1, ", ");

$sql2 = rtrim($sql2, ", ");

$sql = $sql1 . $sql2 . ")";



echo "<b>$sql</b>";


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 8 posts ] 

All times are UTC - 5 hours


Who is online

Users browsing this forum: No registered users and 7 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB® Forum Software © phpBB Group