Problem with INSERT!
I am trying to INSERT data into a database which has been POSTED via a html script. The posts have worked have echoed and get the right data.
The error is saying that there is a syntax error, but I have checked brackets, quotes etc and can't spot anything wrong!
Can anyone see something I am missing?
$fback_sql = "INSERT INTO (feedback title, firstname, lastname, email, comments)
$fback_res = mysqli_query($mysqli, $fback_sql) or die(mysqli_error($mysqli));
$header = "From: email@example.com" . "\r\n";
$to = ('".$_POST["email"]."');
$subject = "Feedback";
$txt = "Thank you for your feedback. \nWe will read your comments and email you again as to our actions";
mail($to, $subject, $txt, $header);
mail("firstname.lastname@example.org", "Posting", "A feedback posting has been sent");
This is invalid:
INSERT INTO (feedback title, .... Perhaps you mean
INSERT INTO feedback (title, ...?
Noticed you are using mysqli. You should used prepared statements to save the trouble from needing to run through a real_escape_string. As is, this is open to SQL Injection.
Yes, i also recommend you use:
Originally Posted by Fou-Lu
$name = mysql_real_escape_string( $_POST['name'] );
Ummm...Clawed: FouLu is saying that *IF* he uses prepared statements then he will not *NEED* to use mysql_real_escape_string.
Which is not only correct, but much better than mysql_real_escape_string.
If you don't know about prepared statements, then time to read up on them.
Oh, i didn't realise he was using MySQLi
Originally Posted by Old Pedant