Level Extreme platform
Subscription
Corporate profile
Products & Services
Support
Legal
Français
Single quote
Message
From
05/03/2009 01:14:13
 
General information
Forum:
Internet
Category:
Active Server Page
Title:
Miscellaneous
Thread ID:
01385403
Message ID:
01385710
Views:
22
>>Hi
>>
>>
>>I have a problem with users entering ' in a field on a classic asp page which is then used to create an SQL string which then fails.
>>
>>Whats the quickest solution to this problem.
>>
>>The system is on maintenance only so I'm really looking for something that requires minimal changes.
>>
>>
>>Thanks
>>
>>Nick
>
>Either use parameters or replace the input string with double '' (you should double the single quote). The first solution is much better.

Thanks Naomi

at the moment there's no justification for the extra work involved in switching to parameters.

Nick
Previous
Reply
Map
View

Click here to load this message in the networking platform