Results 1 to 7 of 7

Thread: sql syntax query...

  1. #1
    Join Date
    Jun 2006

    sql syntax query...

    Hi all:
    I'm struggling to get this to work in PHP:
    PHP Code:
    $sql "INSERT INTO data (date, yname, ymail, cpname, ctname, email, ctphone, msg_type, session, session_date, notes)";
    $sql .="VALUES(NOW(),'$yname','$ymail','$cpname',','$ctname','$email','$ctphone','$type','$session','$date','$notes')";
    $result=mysql_query($sql$cid) or die(mysql_error()); 
    I'm just getting - check your syntax.
    What am I doing wrong?

  2. #2
    Join Date
    Jun 2006
    I have altered the apostrophe - and now the message just reads the error.

  3. #3
    Join Date
    Nov 2008
    Try this:

    PHP Code:
    INSERT INTO `data` (`date`, `yname`, `ymail`, `cpname`, `ctname`, `email`, `ctphone`, `msg_type`, `session`, `session_date`, `notes`) VALUES(NOW(),'$yname','$ymail','$cpname','$ctname','$email','$ctphone','$type','$session','$date','$notes'
    Also it's helpful if you post the error you got.

  4. #4
    Join Date
    Jun 2006
    Hi Mindzai - this is how it looks.

    the form, on a separate page:
    HTML Code:
    <form action="process1.php" method="post" name="data" id="data">
        	<table width="383" border="0" cellpadding="5" cellspacing="5">
              <caption align="top">
                <strong>About you</strong>
                <td width="163">Your name</td>
                <td width="185"><input name="yname"/></td>
                <td>Your email</td>
                <td><input name="ymail" /></td>
                <td>Your phone</td>
                <td><input name="yphone" /></td>
    <table  border="0" cellspacing="5" cellpadding="5">
    <caption align="top">
        <strong>About the recipient</strong>
        <td width="162">Company name</td>
        <td><input name="cpname"/></td>
        <td>Contact name</td>
        <td><input name="ctname" length="25" /></td>
        <td>Contact phone</td>
        <td><input name="ctphone" /></td>
        <td><input name="email" /></td>
      <table  border="0" cellspacing="5" cellpadding="5">
      <caption align="top">
        <strong>About the message</strong>
        <td>Type of message</td>
            <input type="radio" name="RadioGroup1" value="1" id="RadioGroup1_0" />
            Few Appts</label>
          <br />
            <input type="radio" name="RadioGroup1" value="2" id="RadioGroup1_1" />
            Company Recruitment</label>
          <br />
      <table border="0" cellspacing="5" cellpadding="5">
      <caption align="top">
        <strong>About the session</strong>
        <td>Session to promote</td>
        <td><input name="session" /></td>
        <td>Date of session</td>
        <td><input name="date" id="date"><a href="javascript:NewCal('date','ddmmyyyy')"><img src="calendar/cal.gif" width="16" height="16" border="0" alt="Pick a date"></a></td>
        <td><p>Any general notes <br />
            <span class="style3"><em>not for message</em></span><em></em></p>
        <td><textarea name="comments" cols="25" rows="5" id="comments"></textarea></td>
        <td><input type="reset" value="reset" /></td>
        <td><input type="submit" value="send!" /></td>
    fairly straightforward.
    The php looks like like this:
    PHP Code:
    //details sent from form
    $to $email;
    $subject "12 seconds";

    //get file according to radio selection
    $myFile "header".$type.".txt";
    $fh fopen($myFile'r');
    $theData fread($fhfilesize($myFile));

    /*login to mysql*/
    require_once 'mysql_login.php';
    /*create query*/
    $sql "INSERT INTO `data` (`date`, `yname`, `ymail`, `cpname`, `ctname`, `email`, `ctphone`, `msg_type`, `session`, `session_date`, `notes`) VALUES(NOW(),'$yname','$ymail','$cpname','$ctname','$email','$ctphone','$type','$session','$date','$notes')";
    $result=mysql_query($sql$cid) or die(mysql_error());
            if (!
    mysql_query($sql$cid))    {
    'Entered on database';
            } else    {
    'Please contact the help desk!';
    including your changes.
    three issues come up:

    first, my mistake - there are blank fields being added to the database. It does not include the info from the form, although the datetime column is being filled in by php
    second, i'm struggling to get mysql to show what the error is
    third, why does it enter two lines into mysql?

  5. #5
    Join Date
    Nov 2008
    1 - have you checked the values are being correctly received by the processing script? What is the result of the folowing code placed at the top of process1.php

    PHP Code:
    echo '<pre>';
    2. It isn't showing you an error because there is no error to show. If the data is getting inserted the query is working.

    3. Because you are calling the mysql_query() function twice. Replace

    PHP Code:
    if (!mysql_query($sql$cid)) { 

    PHP Code:
    if (!$result) { 

  6. #6
    Join Date
    Apr 2007
    A couple of general notes on your script.

    When debugging SQL echo the queries to the page (or log or mail them to yourself). Comment out the bit where you run them and copy them into a CLI (command line interface) like putty.exe. You'll see what is going to get run before running it so can carefully look through it to see any potential dangerous errors. You get the error direct from the SQL server as well which might be less cryptic then the one from the PHP function.

    Renaming POST variables for no reason serves no purpose. It just means you don't know where the values came from and may not realize later in a script that the variable contains user inputted values and forget to sanitize correctly. Your statement is currently wide open to SQL injection.

    Any information that comes from any where but your scripts (POST, GET, opens URLs etc) needs to be sanitized and validated. Even radio button and checkboxes. Any and all or your vulnerable to attack.
    Anti Linux rants are usually the result of a lack of Linux experience, while anti Windows rants are usually a result of a lot of Windows experience.

  7. #7
    Join Date
    Jun 2006

    Now sorted

    Thanks all - will follow up with the completed code, but in the meantime, Mindzai, the mysl_query, very useful.

    SyCo,ta 4 the reminder

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
HTML5 Development Center



X vBulletin 4.2.2 Debug Information

  • Page Generation 0.10830 seconds
  • Memory Usage 2,954KB
  • Queries Executed 15 (?)
More Information
Template Usage (34):
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_global_above_footer
  • (1)ad_global_below_navbar
  • (1)ad_global_header1
  • (1)ad_global_header2
  • (1)ad_navbar_below
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)ad_thread_first_post_content
  • (1)ad_thread_last_post_content
  • (1)bbcode_html
  • (6)bbcode_php
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)headinclude_bottom
  • (7)memberaction_dropdown
  • (1)navbar
  • (4)navbar_link
  • (1)navbar_moderation
  • (1)navbar_noticebit
  • (1)navbar_tabs
  • (2)option
  • (7)postbit
  • (7)postbit_onlinestatus
  • (7)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available (6):
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files (26):
  • ./showthread.php
  • ./global.php
  • ./includes/class_bootstrap.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/functions_navigation.php
  • ./includes/class_friendly_url.php
  • ./includes/class_hook.php
  • ./includes/class_bootstrap_framework.php
  • ./vb/vb.php
  • ./vb/phrase.php
  • ./includes/functions_facebook.php
  • ./includes/functions_calendar.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_notice.php
  • ./packages/vbattach/attach.php
  • ./vb/types.php
  • ./vb/cache.php
  • ./vb/cache/db.php
  • ./vb/cache/observer/db.php
  • ./vb/cache/observer.php 

Hooks Called (73):
  • init_startup
  • friendlyurl_resolve_class
  • init_startup_session_setup_start
  • database_pre_fetch_array
  • database_post_fetch_array
  • init_startup_session_setup_complete
  • global_bootstrap_init_start
  • global_bootstrap_init_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • load_show_variables
  • load_forum_show_variables
  • global_state_check
  • global_bootstrap_complete
  • global_start
  • style_fetch
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • strip_bbcode
  • friendlyurl_clean_fragment
  • friendlyurl_geturl
  • forumjump
  • cache_templates
  • cache_templates_process
  • template_register_var
  • template_render_output
  • fetch_template_start
  • fetch_template_complete
  • parse_templates
  • fetch_musername
  • notices_check_start
  • notices_noticebit
  • process_templates_complete
  • friendlyurl_redirect_canonical
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • memberaction_dropdown
  • tag_fetchbit
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • build_navigation_data
  • build_navigation_array
  • check_navigation_permission
  • process_navigation_links_start
  • process_navigation_links_complete
  • set_navigation_menu_element
  • build_navigation_menudata
  • build_navigation_listdata
  • build_navigation_list
  • set_navigation_tab_main
  • set_navigation_tab_fallback
  • navigation_tab_complete
  • fb_like_button
  • showthread_complete
  • page_templates