homepage Welcome to WebmasterWorld Guest from 54.146.175.204
register, free tools, login, search, pro membership, help, library, announcements, recent posts, open posts,
Become a Pro Member
Home / Forums Index / Microsoft / Microsoft IIS Web Server and ASP.NET
Forum Library, Charter, Moderators: ocean10000

Microsoft IIS Web Server and ASP.NET Forum

    
Inputting single code string data
pwint

5+ Year Member



 
Msg#: 2939 posted 4:30 pm on Aug 22, 2005 (gmt 0)

Hi
I have a problem in inputing single code(') string into the SQL database. I wrote in ASP language and connect to the SQL server to insert the data.
If the data contains single code string (e.g women's group)the syntax error appears and it stops.
I tried to change the double code(")instead of single one to insert the data and then, it also has error "does not permit column name ...." or something like that.
How can i solve the problem to input the data that contains single code(')?
Any help appreciated. Thanks.

 

mattglet

WebmasterWorld Senior Member 10+ Year Member



 
Msg#: 2939 posted 4:53 pm on Aug 22, 2005 (gmt 0)

Here's a past post that includes a function you can call (see the last post).

[webmasterworld.com...]

mrMister

WebmasterWorld Senior Member 5+ Year Member



 
Msg#: 2939 posted 7:03 pm on Aug 22, 2005 (gmt 0)

Simply replacing the quotes is a bad habit to get in to. You create a lot of security vulnerabilities by using ad-hoc SQL statements like that.

Use your favourite search engine and search for information on parameterized SQL queries in ASP.

Global Options:
 top home search open messages active posts  
 

Home / Forums Index / Microsoft / Microsoft IIS Web Server and ASP.NET
rss feed

All trademarks and copyrights held by respective owners. Member comments are owned by the poster.
Home ¦ Free Tools ¦ Terms of Service ¦ Privacy Policy ¦ Report Problem ¦ About ¦ Library ¦ Newsletter
WebmasterWorld is a Developer Shed Community owned by Jim Boykin.
© Webmaster World 1996-2014 all rights reserved