Posted by Jim Michaels on 02/14/06 01:11
<ces.fci@gmail.com> wrote in message
news:1138901184.770495.214910@g43g2000cwa.googlegroups.com...
> Be sure to escape any values that are in your queryt, e.g:
> $myfile = mysql_real_escape_string($myfile);
> $sql = "update products set smallpicname ='$myfile' where id='$idvar'";
$sql = "update products set smallpicname ='$myfile' where id=$idvar";
it's not good SQL etiquette to put a number in a quotes unless the columns
is defines as some CHAR type.
>
Navigation:
[Reply to this message]
|