i can't see where is the Invalid character with the SQL statement below. i can't see where i miss any character or i added extra characters.

mySQL = "UPDATE table SET col1 = '"_& rA & "', col2 = " & rB & ", col3 = " & rC & ", col4 = " & rD & ", col5 = " & rE ", col6 = " & rF & " WHERE primaryKey = '" & primary "'"

Dani AI

Generated

Two quick checks that almost always fix this kind of "invalid character" when building SQL in classic ASP: mismatched quotes in the VBScript string and unescaped single quotes inside the data. As pointed out, a stray double quote at the end will break the VBScript literal. As showed a similar build, also confirm every concatenation uses the & operator and that no & or quote got dropped or doubled during copy/paste.

Debugging steps you can apply right away:

  • Build the SQL into a string variable, then output it (do not execute) with Response.Write or Server.HTMLEncode so you can inspect exact characters.
  • Make sure text values are wrapped in single quotes in the final SQL, numeric values are not, and every VBScript literal is enclosed in double quotes.
  • Escape any single quotes inside user data with a Replace call before concatenation to prevent SQL syntax errors and injection.

Example (debug + escaping):

safeA = Replace(valueA, "'", "''")
safePk = Replace(pkValue, "'", "''")
sqlText = "UPDATE MyTable SET col1 = '" & safeA & "', col2 = " & valueB & " WHERE id = '" & safePk & "'"
Response.Write Server.HTMLEncode(sqlText)

If the printed SQL looks correct but still errors, paste that output here and we can pinpoint the exact offending character. Also consider moving to parameterized ADO commands to avoid concatenation errors and SQL injection altogether.

Recommended Answers

All 2 Replies

possible double quotes at end, but i missed it, sorry.

mySQL = "UPDATE table SET col1 = '"_& rA & "', col2 = " & rB & ", col3 = " & rC & ", col4 = " & rD & ", col5 = " & rE & ", col6 = " & rF & " WHERE primaryKey = '" & primary "'"

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.