miladanimator
Active Member
...
آخرین ویرایش:
public function getSQLValueString($theValue, $theType, $theDefinedValue = "", $theNotDefinedValue = "") {
$theValue = get_magic_quotes_gpc() ? stripslashes($theValue) : $theValue;
$theValue = function_exists("mysql_real_escape_string") ? mysql_real_escape_string($theValue) : mysql_escape_string($theValue);
switch ($theType) {
case "text":
$theValue = ($theValue != "") ? "'" . $theValue . "'" : "NULL";
break;
case "long":
case "int":
$theValue = ($theValue != "") ? intval($theValue) : "NULL";
break;
case "double":
$theValue = ($theValue != "") ? "'" . doubleval($theValue) . "'" : "NULL";
break;
case "date":
$theValue = ($theValue != "") ? "'" . $theValue . "'" : "NULL";
break;
case "defined":
$theValue = ($theValue != "") ? $theDefinedValue : $theNotDefinedValue;
break;
}
return $theValue;
}
$sql = sprintf("INSERT INTO tbladvertisment (name,address,link,position,status) VALUES (%s,%s,%s,%s,%s)",
getSQLValueString($_POST['name'],'text'),
getSQLValueString($address,'text'),
getSQLValueString($_POST['link'],'text'),
getSQLValueString($_POST['position'],'int'),
getSQLValueString($_POST['status'],'int'));