in reply to cleaning up sql from file
Yep, the "catapostrophe" is VERY dangerous with SQL -- it is a principle means of SQL injection attacks (google that).
One way to prevent this is to parse the string to escape the apostrophes before it goes into the db.
I believe most SQL db's use double apostrophes ('' = TWO ' characters, NOT a double quote) for this, look in your docs.
Another way to prevent this is by using stored procedures (google again...)
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: cleaning up sql from file
by Corion (Patriarch) on Oct 17, 2010 at 19:46 UTC | |
by ag4ve (Monk) on Oct 17, 2010 at 20:21 UTC | |
by Corion (Patriarch) on Oct 17, 2010 at 20:25 UTC |