penfold1992
Registered User.
- Local time
- Today, 00:52
- Joined
- Nov 22, 2012
- Messages
- 169
Hello,
I have been looking into a problem I have which appears quite common (the apostrophe problem!)
I've seen a common solution is to double up the apostrophe, replacing ' with " to avoid the special character however i also hear of another solution using "parameters".
I tried have a look around on the internet and got confused so I thought maybe it would be better to ask here.
I just want to change my INSERT INTO and UPDATE commands to be able to use this (to prevent a potential sql injection)
also i think its important to know im using DOA to code? (not sure if its important) either way, what can you tell me about this as a way around the apostrophe problem?
I have been looking into a problem I have which appears quite common (the apostrophe problem!)
I've seen a common solution is to double up the apostrophe, replacing ' with " to avoid the special character however i also hear of another solution using "parameters".
I tried have a look around on the internet and got confused so I thought maybe it would be better to ask here.
I just want to change my INSERT INTO and UPDATE commands to be able to use this (to prevent a potential sql injection)
also i think its important to know im using DOA to code? (not sure if its important) either way, what can you tell me about this as a way around the apostrophe problem?