Solved

ASP Unclosed quotes error message

Posted on 2007-03-27
3
205 Views
Last Modified: 2011-10-03
I have an application that people can paste into an input box information from a Word Document.  The data gets posted to a SQL Server database.

However...if the text includes an apostrophe like this line

in one of Boca Raton's finest

Theres an error message.  What can I do to get it to accept the apostrophe?  Error message follows

Incorrect syntax near 's'.
Unclosed quotation mark after the character string ' where txtAdID=4134'.
Description: An unhandled exception occurred during the execution of the current web request. Please review the stack trace for more information about the error and where it originated in the code.

Exception Details: System.Data.SqlClient.SqlException: Incorrect syntax near 's'.
Unclosed quotation mark after the character string ' where txtAdID=4134'.

Source Error:


Line 56:         sSQL = sSQL & " where txtAdID=" & Request.QueryString("txtAdID")
Line 57:         oCom2.CommandText = sSQL
Line 58:         oCom2.ExecuteNonQuery()
Line 59:         oCom2.Dispose()

 
0
Comment
Question by:lrbrister
  • 2
3 Comments
 
LVL 37

Expert Comment

by:samtran0331
ID: 18802148
you should always use parameterized queries:
http://aspnet101.com/aspnet101/tutorials.aspx?id=1

doing sql like this:
sSQL = sSQL & " where txtAdID=" & Request.QueryString("txtAdID")

is bad...it leaves you open to sql injection attacks as well as problems like this with the apostrophe
0
 
LVL 37

Accepted Solution

by:
samtran0331 earned 500 total points
ID: 18802165
here's another article on parameterized queries:
http://www.4guysfromrolla.com/webtech/092601-1.shtml

also, the first page gives you a "quick fix" for your apostrophe problem...but I'd highly recommend that you use parameterized queries and/or stored procedures
0
 

Author Comment

by:lrbrister
ID: 18802357
samtran0331
  This does get executed in a stored procedure.  But thanks for the info and the link
Points being awarded now
0

Featured Post

Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Class Library Dynamics For Connectstring Information 2 17
Help with simplifying SQL 6 47
Run time Error 4 34
SQL Login 17 37
In this article I will describe the Copy Database Wizard method as one possible migration process and I will add the extra tasks needed for an upgrade when and where is applied so it will cover all.
If you need to start windows update installation remotely or as a scheduled task you will find this very helpful.
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

939 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now