Form Help


Posted on 16th Feb 2014 07:03 pm by admin

Here is the form:

Line number On/Off | Expand/Contract<? include("../include/session.php"); ?> <?php if ($submit) { $sql = "UPDATE productimages SETtitle='".$_POST['title']."', upjpg='".$_POST['upjpg']."',uptiff='".$_POST['uptiff']."',uppng='".$_POST['uppng']."', chungshi='".$_POST['chungshi']."', stretchwalker='".$_POST['stretch_walker']."',akaishi='".$_POST['akaishi']."', bellamargiano='".$_POST['bellamargiano']."',mbt='".$_POST['mbt']."', upthumb='".$_POST['upthumb']."'where id ='".mysql_real_escape_string($_POST['id'])."'"; $result = mysql_query($sql) or die(mysql_error()); print("Product Added"); } else { $result = mysql_query("SELECT * FROM productimages WHERE id = '$id'"); while ($row=mysql_fetch_array($result)) { $id = $row[id]; $uptiff = $row[uptiff]; $upjpg = $row[upjpg]; $uppng = $row[uppng]; $chungshi = $row[chungshi]; $stretchwalker = $row[stretchwalker]; $akaishi = $row[akaishi]; $bellamargiano = $row[bellamargiano]; $mbt = $row[mbt]; $upthumb = $row[upthumb]; } print (" <form method=post action=productimages2.php>Product Title:
<input type=text name=title size=60>
Did you know?Explore Trending and Topic pages for more stories like this.

Choose Categories that this story is relevant to:
<input type=checkbox name=chungshi value=1> Chung Shi
<input type=checkbox name=stretchwalker value=1> Stretchwalker
<input type=checkbox name=akaishi value=1> Akaishi
<input type=checkbox name=bellamargiano value=1> Bellamargiano
<input type=checkbox name=mbt value=1> MBT

<table width=500 cellpadding=0 cellspacing=0> <tr><td colspan=2 class=top><strong>Images</strong></td></tr> <tr><td>Upload JPG</td><td>
<input type=file name=upjpg></td></tr><tr><td colspan=2 class=top> </td></tr><tr><td>Upload TIFF</td><td>
<input type=file name=uptiff> </td></tr><tr><td colspan=2 class=top> </td></tr><tr><td>Upload PNG</td><td>
<input type=file name=uppng> </td></tr><tr><td colspan=2 class=top> </td></tr><tr><td>Upload Thumbnail</td><td>
<input type=file name=upthumb> </td></tr></table>
<input type=submit name=submit value=submit>

</form> "); } ?>

Here is the sql connection:

Line number On/Off | Expand/Contract<?php$con = mysql_connect("localhost", "user", "pass");if (!$con) { die('Could not connect: ' . mysql_error()); }mysql_select_db("database", $con);$sql = "insert into productimages ('".mysql_real_escape_string($_POST['title'])."', '".mysql_real_escape_string($_POST['chungshi'])."', '".mysql_real_escape_string($_POST['stretchwalker'])."', '".mysql_real_escape_string($_POST['akaishi'])."', '".mysql_real_escape_string($_POST['bellamargiano'])."', '".mysql_real_escape_string($_POST['mbt'])."', '".mysql_real_escape_string($_POST['upjpg'])."', '".mysql_real_escape_string($_POST['uptiff'])."', '".mysql_real_escape_string($_POST['uppng'])."', '".mysql_real_escape_string($_POST['upthumb'])."')";mysql_query($sql) or die(mysql_error()." <br /> $sql"); echo "The following information was entered into the database


";echo "<b>Title:</b>&nbsp;$_POST[title]
"; echo "Thanks for taking the time to submit your information."; mysql_close($con); ?>

And here is the error I'm getting:

Quote:You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''asdfasdf', '', '', '', '1', '', '', '', '', '')' at line 1
insert into productimages ('asdfasdf', '', '', '', '1', '', '', '', '', '')
No comments posted yet

Your Answer:

Login to answer
296 Like 11 Dislike
Previous forums Next forums
Other forums

is this the proper use of mysql_real_escape_string() to prevent sql injections?
i was wondering is this the proper use of mysql_real_escape_string() to prevent sql injections? any

question about stripslashes and real_escape_string
im cleaning up an old app that I wrote fixing some of the vulernabilities from attacks.

I hav

Newb advice
Hi all,

I'm a flash front end designer and I've taken on a project that needs some back end p

Reading waves
Hi,

I am trying to find a way of finding the highs and lows on a graph line, the line points

Connecion issue
Hi,

For some reason, I keep getting this error when trying to connect:

Warning: mysql_

Basic Forum Tutorial
Hi, I'm new to PHP. I want to build a basic forum for my site using PHP and MySQL. I've searched t

what are '%S%', '%E%'
for example when i see Code: [Select]printf("Hello %srn", $name);
what does %s means

Solution to the FindControl problem
I have seen may posts about having problems with the FindControl method. Most seem to come about bec

Easy administration on MySQL databases
My website is database driven and I am very tired of manually making queries to my tables in order t

Oracle Connectivity
Hi Every One,

Can we access SAP from oracle database.If it possible then please spec

Sign up to write
Sign up now if you have flare of writing..
Login   |   Register
Follow Us
Indyaspeak @ Facebook Indyaspeak @ Twitter Indyaspeak @ Pinterest RSS



Play Free Quiz and Win Cash