Forum Moderators: coopster
<?php
if(isset($_POST['submitted']) == 1) {
$title = mysqli_real_escape_string($dbc, $_POST['$title']);
$header = mysqli_real_escape_string($dbc, $_POST['$header']);
$body = mysqli_real_escape_string($dbc, $_POST['$body']);
$q = "INSERT INTO `pages` (`userid`, `title`, `header`, `body`) VALUE ($_POST[$userid], '$title', '$header', '$body')";
$r = mysqli_query($dbc, $q) or die(mysqli_error($dbc));
if($r) {
$message = '<p>Page was added.</p>';
} else {
$message = '<p>Page could not be added due to: </p>'.mysqli_error($dbc);
$message .= '<p>'.$q.'</p>';
} // end if inner
} // end if outer
?>
$title = mysqli_real_escape_string($dbc, $_POST['$title'])You're defining a variable by referring to the variable that you're currently defining.
<?php
if(isset($_POST['submitted']) == 1) {
// removes special characters
$title = mysqli_real_escape_string($dbc, $_POST['title']);
$header = mysqli_real_escape_string($dbc, $_POST['header']);
$body = mysqli_real_escape_string($dbc, $_POST['body']);
// removes backslashes
$title = stripslashes($_POST['title']);
$header = stripslashes($_POST['header']);
$body = stripslashes($_POST['body']);
$q = "INSERT INTO `pages` (`title`, `header`, `body`) VALUE ('$title', '$header', '$body')";
$r = mysqli_query($dbc, $q) or die(mysqli_error($dbc));
if($r) {
$message = '<p>Page was added.</p>';
} else {
$message = '<p>Page could not be added due to: </p>'.mysqli_error($dbc);
$message .= '<p>'.$q.'</p>';
} // end if inner
} // end if outer
?>
<?php
if(isset($_POST['submitted']) == 1) {
$header = stripslashes($_REQUEST['header']);
$header = mysqli_real_escape_string($dbc, $header);
$title = stripslashes($_REQUEST['title']);
$title = mysqli_real_escape_string($dbc, $title);
$body = stripslashes($_REQUEST['body']);
$body = mysqli_real_escape_string($dbc, $body);
$q = "INSERT INTO `pages` (`header`, `title`, `body`) VALUE ('$header', '$title', '$body')";
$r = mysqli_query($dbc, $q) or die(mysqli_error($dbc));
if($r) {
$message = '<p>Page was added.</p>';
} else {
$message = '<p>Page could not be added due to: </p>'.mysqli_error($dbc);
$message .= '<p>'.$q.'</p>';
} // end if inner
} // end if outer
?>