PhotoPost Photo Gallery Sales PhotoPost Sales Toll Free Phone Number
Mon-Fri 9am-4pm EST
  PhotoPost Photo Sharing Photo Gallery    Visualize community tm
| | | | | | | | |

Go Back   PhotoPost Community > PhotoPost Support > PhotoPost Pro Support Forums > Photopost Pro Bug Reports

Photopost Pro Bug Reports Post post installation PhotoPost Pro problems here.

Reply
 
LinkBack Thread Tools Rate Thread Display Modes
Old April 18th, 2011, 06:13 PM   #1 (permalink)
vei
Junior Member
Verified Customer
 
Join Date: Jan 2006
Posts: 12
SQl Insert Problem when Quote in String

An error was encountered during execution of the query:

INSERT INTO photos (id,user,userid,cat,storecat,storeid,date,title,description,keywords,bigimage,width,height,
filesize,medwidth,medheight,medsize,approved,watermarked,allowprint,extra1,extra2,
extra3,extra4,extra5,extra6,ipaddress)
VALUES (NULL,'Joe'smom', 6123, 62, '576', '3053', 1134262636, 'Retrieving Santa--Golden Style!',
'Max and his new brother Wrigley---going over their lists with Santa', '', 'puppy_015.jpg', 640, 480, 166716, 0,
0, 0, 1, '','','','',
'','','','','72.9.0.200')

The query returned with an errorcode of:

You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'smom', 6123, 62, '576', '3053', 1134262636, 'Retrieving Santa--Golden Style!',
' at line 4
vei is offline   Reply With Quote
Old April 18th, 2011, 08:25 PM   #2 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,698
I do not see how your error can happen. In our image-inc.php file we explicitly addslashes where needed. Most variables are typecast and addslashes is used in that function. Now a username is not typecast so that specifically is addslashed right before the query so the 64 million dollar question is why is your name not addslashes?

Code:
Content visible to verified customers only.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Old April 20th, 2011, 05:10 PM   #3 (permalink)
vei
Junior Member
Verified Customer
 
Join Date: Jan 2006
Posts: 12
that userid comes from the vB3 user database.

vB allows (') in the username -- although I have since put a regexp on to prevent special characters from being used. Nonetheless, we do have a few users with a (') in their username.
vei is offline   Reply With Quote
Old April 20th, 2011, 06:32 PM   #4 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,698
right but thats why I am a little confused as said we EXPLICITLY addslashes which means you should not have an issue. Your query shows there is no addslash being done.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
pp-inc.php string problem sherpa Photopost Pro How Do I...? 5 March 12th, 2010 06:07 AM
SQL problem wfcmod Photopost Pro Bug Reports 2 October 22nd, 2006 09:49 AM
Problem installing Reviewpost - SQL error. MikeWarner ReviewPost Installation & Upgrades 2 February 25th, 2006 06:25 PM
Invalid SQL: INSERT INTO adv_gallery_customfields_entries PageUp Installs and Upgrade - vBulletin 3.0.X 3 March 30th, 2005 10:34 AM
Zipcode SQL Insert MRaburn Classifieds Bug Reports 3 February 10th, 2005 10:28 PM


All times are GMT -5. The time now is 10:57 AM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0