Hello,
I want to insert single or double quotes into mysql without using \ or anything else i tried mysql_real_escape_string but it did not work it gives SQL Syntax Error : Check what to use near error...Plz Help... Here's the code...
<?php
$name = isset($_POST['name']) ? $_POST["name"] : "";
$description = isset($_POST['description']) ? $_POST["description"] : "";
$field1= isset($_POST['field1']) ? $_POST["field1"] : "";
$field2= isset($_POST['field2']) ? $_POST["field2"] : "";
$field3= isset($_POST['field3']) ? $_POST["field3"] : "";
$field4= isset($_POST['field4']) ? $_POST["field4"] : "";
$field5= isset($_POST['field5']) ? $_POST["field5"] : "";
$field6= isset($_POST['field6']) ? $_POST["field6"] : "";
$field7= isset($_POST['field7']) ? $_POST["field7"] : "";
$field1a= isset($_POST['field1a']) ? $_POST["field1a"] : "";
$field2a= isset($_POST['field2a']) ? $_POST["field2a"] : "";
$field3a= isset($_POST['field3a']) ? $_POST["field3a"] : "";
$field4a= isset($_POST['field4a']) ? $_POST["field4a"] : "";
$field5a= isset($_POST['field5a']) ? $_POST["field5a"] : "";
$field6a= isset($_POST['field6a']) ? $_POST["field6a"] : "";
$field7a= isset($_POST['field7a']) ? $_POST["field7a"] : "";
$details = isset($_POST['details']) ? $_POST["details"] : "";
$year = isset($_POST['year']) ? $_POST["year"] : "";
include_once "scripts/connect_to_mysql.php";
$sql = mysql_query("INSERT INTO people (name, field1, field2, field3, field4, field5, field6, field7, description, year, field1a, field2a, field3a, field4a, field5a, field6a, field7a) VALUES ('$name','$field1','$field2','$field3','$field4','$field5','$field6','$field7','$description','$year','$field1a','$field2a','$field3a','$field4a','$field5a','$field6a','$field7a')") or die (mysql_error());
$id = mysql_insert_id();
mkdir("../people/$id", 0755);
$newname = "image01.jpg";
$place_file = move_uploaded_file( $_FILES['fileField']['tmp_name'], "../people/$id/".$newname);
header("Location: addperson.php");
?>
Plz Help