Solved

SQL statement not working

Posted on 2007-03-18
7
170 Views
Last Modified: 2008-02-01
Is the $_GET statement typed wrong here?

$SQLstr = mysql_query("SELECT strProviderservice, strCompanyname, strOwner, strAddress, strTown, strZipcode, strPhone, str2ndphone, strMobile, strPager, strFax, strEmail, strWebsite, strlicense, strInsured, strBonded, strHours, str24houremerg, strOtherservices, strServicearea, strInbusiness_since, strServicesoffered, strFreeestimate, strWorkguaranteed, strProvidertagline, strAd_size, strImage FROM tblAdspace WHERE providerID = " $_GET["providerID"]
or die("SQL statement is not working");
0
Comment
Question by:pingeyeg
  • 3
  • 2
  • 2
7 Comments
 
LVL 27

Assisted Solution

by:yodercm
yodercm earned 300 total points
ID: 18744787
NEVER EVER use a form input directly in a query!!  It's wide open to SQL Injection hacking.



$providerID = $_GET["providerID"];

Then

$SQLstr = mysql_query("SELECT strProviderservice, strCompanyname, strOwner, strAddress, strTown, strZipcode, strPhone, str2ndphone, strMobile, strPager, strFax, strEmail, strWebsite, strlicense, strInsured, strBonded, strHours, str24houremerg, strOtherservices, strServicearea, strInbusiness_since, strServicesoffered, strFreeestimate, strWorkguaranteed, strProvidertagline, strAd_size, strImage FROM tblAdspace WHERE providerID = mysql_real_escape_string($providerID")
or die("SQL statement is not working");
0
 
LVL 27

Assisted Solution

by:yodercm
yodercm earned 300 total points
ID: 18744793
Oops, missing )....

$SQLstr = mysql_query("SELECT strProviderservice, strCompanyname, strOwner, strAddress, strTown, strZipcode, strPhone, str2ndphone, strMobile, strPager, strFax, strEmail, strWebsite, strlicense, strInsured, strBonded, strHours, str24houremerg, strOtherservices, strServicearea, strInbusiness_since, strServicesoffered, strFreeestimate, strWorkguaranteed, strProvidertagline, strAd_size, strImage FROM tblAdspace WHERE providerID = mysql_real_escape_string($providerID)")
or die("SQL statement is not working");
0
 
LVL 1

Author Comment

by:pingeyeg
ID: 18744805
Ok, right now I am getting the "SQL statement is not working" string.
0
Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

 
LVL 1

Author Comment

by:pingeyeg
ID: 18744821
When using mysql_error() I get FUNCTION providers.mysql_real_escape_string does not exist
0
 
LVL 50

Accepted Solution

by:
Steve Bink earned 200 total points
ID: 18744880
$query = "SELECT strProviderservice, strCompanyname, strOwner, strAddress, strTown, strZipcode, strPhone, str2ndphone, strMobile, strPager, strFax, strEmail, strWebsite, strlicense, strInsured, strBonded, strHours, str24houremerg, strOtherservices, strServicearea, strInbusiness_since, strServicesoffered, strFreeestimate, strWorkguaranteed, strProvidertagline, strAd_size, strImage FROM tblAdspace WHERE providerID = " . mysql_real_escape_string($providerID);
$result = mysql_query($query) or die("SQL statement is not working");
0
 
LVL 1

Author Comment

by:pingeyeg
ID: 18744896
Is that just another way of writing the sql query?  Putting the mysql_query at the bottom?
0
 
LVL 50

Expert Comment

by:Steve Bink
ID: 18761288
Just better organization for readability.  The problem in the statement was a combo of quotes and parenthesis.  
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
calculated column 12 74
what is best version of php to use 6 44
xampp tool 12 24
Configuring a checkbox in CSS and php 18 30
Introduction HTML checkboxes provide the perfect way for a web developer to receive client input when the client's options might be none, one or many.  But the PHP code for processing the checkboxes can be confusing at first.  What if a checkbox is…
Nothing in an HTTP request can be trusted, including HTTP headers and form data.  A form token is a tool that can be used to guard against request forgeries (CSRF).  This article shows an improved approach to form tokens, making it more difficult to…
Explain concepts important to validation of email addresses with regular expressions. Applies to most languages/tools that uses regular expressions. Consider email address RFCs: Look at HTML5 form input element (with type=email) regex pattern: T…
The viewer will learn how to create a basic form using some HTML5 and PHP for later processing. Set up your basic HTML file. Open your form tag and set the method and action attributes.: (CODE) Set up your first few inputs one for the name and …

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now