Hey guys,
Each time I try to use the form below to add something to a mysql database it doesn't work, I have figured out that it doesn't like apostrophes and won't add anything to the database with one in it.
Form Code:
I was recommended to add this code to fix the issue but it doesn't work either.
Just hoping someone can help me out guys as its driving me nuts
Each time I try to use the form below to add something to a mysql database it doesn't work, I have figured out that it doesn't like apostrophes and won't add anything to the database with one in it.
Form Code:
PHP:
<link rel="stylesheet" href="http://code.jquery.com/ui/1.10.3/themes/smoothness/jquery-ui.css" />
<script src="http://code.jquery.com/ui/1.10.3/jquery-ui.js"></script>
<script src="http://code.jquery.com/jquery-1.9.1.js"></script>
<script>
function focusTextBox(){
var a=2;
var tb = document.getElementById('datepicker');
if(a==2){
$(document).ready(function() {
$( "#datepicker" ).datepicker({ minDate: 0, maxDate: "+18M +0D", showOtherMonths: true,
selectOtherMonths: true, dayNamesMin: ['Sun', 'Mon', 'Tue', 'Wed', 'Thu', 'Fri', 'Sat'],showButtonPanel: true, dateFormat: 'yy-mm-dd' });
});
}else{
$(document).ready(function() {
$( "#datepicker" ).datepicker({ minDate: 1, maxDate: "+18M +0D", dateFormat: 'yy-mm-dd' });
});
}
tb.focus();
}
</script>
<?
//header('Refresh: 20');
$username="*";
$password="*";
$database="*";
$localhost="*";
$editor = "
<option value='phil'>Phil Hopper</option>
<option value='robyn'>Robyn Adamson</option>
<option value='patrick'>Patrick O'Kane</option>
<option value='andrew.robinson'>Andrew Robinson</option>
<option value='Other'>Other</option>
";
?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
<title>Untitled Document</title>
</head>
<body>
<form id="form1" name="form1" method="post" action="insert_project.php">
<table width="200" border="1">
<tr>
<td>Project Name</td>
<td>
<input type='text' name='project_name' value='' />
</tr>
<tr>
<td>Client Name</td>
<td> <input type='text' name='client_name'input value=''>
</td>
</tr>
<tr>
<td>Client Contact Number</td>
<td> <input type='text' name='client_tel'input value=''>
</td>
</tr>
<tr>
<td>Client Email</td>
<td> <input type='text' name='client_email'input value=''>
</td>
</tr>
<tr>
<td>Short Project Description</td>
<td><textarea name="description" cols="17" rows="5"></textarea></td>
</tr>
<tr>
<td>Logos</td>
<td>
<input type='text' name='logos'input value=''>
</tr>
<tr>
<td>Deadline</td>
<td> <div data-role="fieldcontain">
<input type="date" name="deadline" id="deadline" value="date" />
</div>
</td>
</tr>
<tr>
<td>BNL Deadline</td>
<td> <div data-role="fieldcontain">
<input type="date" name="bnl" id="bnl" value="date" />
</div>
</td>
</tr>
<tr>
<td>Project Manager</td>
<td>
<input type='text' name='manager'input value=''>
</tr>
<tr>
<td>Filming</td>
<td>
<input type='text' name='filiming'input value=''>
</tr>
<tr>
<td>Editor</td>
<td>
<select name="editor" id="editor">
<option value=""></option>
<? echo "$editor"?>
</select>
</tr>
<tr>
<td>Dropbox Folder</td>
<td>
<input type='text' name='dropboxfolder'input value=''>
</tr>
<tr>
<td>Music Theme</td>
<td>
<input type='text' name='music'input value=''>
</tr>
<tr>
<td>Songs per project</td>
<td>
<input type='text' name='songs'input value=''>
</tr>
<tr>
<td>Clients expected time</td>
<td>
<input type='text' name='client_time'input value=''>
</tr>
<tr>
<td>Expected Outcome</td>
<td>
<input type='text' name='outcome'input value=''>
</tr>
<tr>
<td>Notes</td>
<td><textarea name="notes" cols="17" rows="5"></textarea></td>
</tr>
</table>
<? mysql_close();?>
<input type="submit" name="Submit" id="Submit" value="Submit" />
</form>
</body>
</html>
I was recommended to add this code to fix the issue but it doesn't work either.
PHP:
function mysql_real_escape_array($array) {
foreach ($array as $key => $value) {
if (is_array($value)) $array[$key] = mysql_real_escape_array($value);
else $array[$key] = mysql_real_escape_string($value);
}
return $array;
}
if (!empty($_GET)) $_GET = mysql_real_escape_array($_GET);
if (!empty($_POST)) $_POST = mysql_real_escape_array($_POST);
if (!empty($_REQUEST)) $_REQUEST = mysql_real_escape_array($_REQUEST);
Just hoping someone can help me out guys as its driving me nuts