Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - ’ replacement
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

’ replacement

 Post Reply Post Reply Page  123>
Author
zMaestro View Drop Down
Senior Member
Senior Member


Joined: 11 May 2003
Location: Egypt
Status: Offline
Points: 1183
Post Options Post Options   Thanks (0) Thanks(0)   Quote zMaestro Quote  Post ReplyReply Direct Link To This Post Topic: ’ replacement
    Posted: 15 April 2004 at 12:21pm

Hi,

I want to replace the ' mark this mark (') since it is entered in text box and supposed to be send to database. and sure it gives error in the sql statement since it closes the statement before the job is done.

how can this be done through the replacement code, i.e. what character am I supposed to exchange it with?

thanks again :)

Back to Top
Semikolon View Drop Down
Senior Member
Senior Member


Joined: 09 September 2003
Location: Norway
Status: Offline
Points: 1718
Post Options Post Options   Thanks (0) Thanks(0)   Quote Semikolon Quote  Post ReplyReply Direct Link To This Post Posted: 15 April 2004 at 1:21pm

strInput = Replace(strInput, "'", "'")

 

ASCII Table

Character Special sign Decimal sign
space    
!   !
" " "
#   #
$   $
%   %
& & &
'   '
(   (
)   )
*   *
+   +
,   ,
-   -
.   .
/   /
0   0
1   1
2   2
3   3
4   4
5   5
6   6
7   7
8   8
9   9
:   :
;   &#59;
<
Back to Top
Mart View Drop Down
Senior Member
Senior Member
Avatar

Joined: 30 November 2002
Status: Offline
Points: 2304
Post Options Post Options   Thanks (0) Thanks(0)   Quote Mart Quote  Post ReplyReply Direct Link To This Post Posted: 15 April 2004 at 1:23pm
If your getting an error when you put ' in it means someone could do a sql injection. Do a google for sql injection.
Back to Top
zMaestro View Drop Down
Senior Member
Senior Member


Joined: 11 May 2003
Location: Egypt
Status: Offline
Points: 1183
Post Options Post Options   Thanks (0) Thanks(0)   Quote zMaestro Quote  Post ReplyReply Direct Link To This Post Posted: 17 April 2004 at 6:29pm

oh no :(

the & character gives me error too since it is sent as querystring

how can I replace the & character?

Back to Top
Semikolon View Drop Down
Senior Member
Senior Member


Joined: 09 September 2003
Location: Norway
Status: Offline
Points: 1718
Post Options Post Options   Thanks (0) Thanks(0)   Quote Semikolon Quote  Post ReplyReply Direct Link To This Post Posted: 18 April 2004 at 5:08am
&amp; LOL

before sending the data to the querystring, run Server.URLEncode() or Server.HTMLEncode()


Edited by Semikolon
Back to Top
zMaestro View Drop Down
Senior Member
Senior Member


Joined: 11 May 2003
Location: Egypt
Status: Offline
Points: 1183
Post Options Post Options   Thanks (0) Thanks(0)   Quote zMaestro Quote  Post ReplyReply Direct Link To This Post Posted: 18 April 2004 at 6:33am

what do they do?

Back to Top
Mart View Drop Down
Senior Member
Senior Member
Avatar

Joined: 30 November 2002
Status: Offline
Points: 2304
Post Options Post Options   Thanks (0) Thanks(0)   Quote Mart Quote  Post ReplyReply Direct Link To This Post Posted: 18 April 2004 at 6:35am
Turn things like & into &amp;... But if you get an error because an & is present you will still get an error with &amp;
Back to Top
Semikolon View Drop Down
Senior Member
Senior Member


Joined: 09 September 2003
Location: Norway
Status: Offline
Points: 1718
Post Options Post Options   Thanks (0) Thanks(0)   Quote Semikolon Quote  Post ReplyReply Direct Link To This Post Posted: 18 April 2004 at 7:02am
is it possible to transfer it in the header instead of the URL?
Back to Top
 Post Reply Post Reply Page  123>

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.