in reply to Re^2: Search 2 columns
in thread Search 2 columns
Consider the following things that can go wrong when generating your SQL:
my $search = "foobar"; printf "WHERE blah LIKE '%$search%' LIMIT %d,%d\n", 1, 2; # ... LIKE '%foobar' ... # ^^ # WHERE blah LIKE '1.000000oobar%' LIMIT 2,0
my $search = "f %d"; printf "WHERE blah LIKE '%$search%' LIMIT %d,%d\n", 1, 2; # WHERE blah LIKE '1.000000 2%' LIMIT 0,0
my $search = "' OR '1' LIKE '1"; printf "WHERE blah LIKE '%$search%' LIMIT %d,%d\n", 1, 2; # WHERE blah LIKE '%' OR '1' LIKE '1%' LIMIT 1,2
Solutions/suggestions:
blokhead
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^4: Search 2 columns
by roboticus (Chancellor) on Sep 22, 2007 at 16:35 UTC | |
by graff (Chancellor) on Sep 23, 2007 at 15:15 UTC | |
by roboticus (Chancellor) on Sep 23, 2007 at 15:50 UTC |