[Date Prev][Date Next][Thread Prev][Thread Next][Minivend by date
][Minivend by thread
]
[mv] why?
****** message to minivend-users from Viktors Rotanovs <viktors@riga.nu> ******
Hi,
i wrote the following part of sql statement:
'[cgi name=address filter=sql]',
and then passed "don't bill me" as POST parameter.
Resulting SQL statement contained:
'don't bill me',
Shouldn't it escape ' ?
--
Best Wishes,
Viktors Rotanovs
I create websites that attract more clients. http://riga.nu/
Riga Latvia +371, Phone 7377-142, GSM 9173-000, FAX 7377-472
-
To unsubscribe from the list, DO NOT REPLY to this message. Instead, send
email with 'UNSUBSCRIBE minivend-users' in the body to Majordomo@minivend.com.
Archive of past messages: http://www.minivend.com/minivend/minivend-list