Forum Moderators: open
$sql = " UPDATE persons SET fn = '".$_POST[firstname]."', sn ='".$_POST[surname]."', cmp = '".$_POST[company]."',";
$sql .=" addr1 = '".$_POST[addr1]."', addr2 = '".$_POST[addr2]."', addr3 = '".$_POST[addr3]."', county = '".$_POST[addr4]."', ";
$sql .=" hph = '".$_POST[phone1]."', wph = '".$_POST[phone2]."', mph1 = '".$_POST[phone3]."', mph2 = '".$_POST[phone4]."', ";
$sql .=" dateOfBirth = '".$dob."', cno = '".$_POST[sky_no]."', payment = '".$_POST[pnote]."', cstat= '".$_POST[cstatus]."', shutoff = '".$shutoff."',";
cannot execute query:You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '' at line 1
// get and edit our information; set a default if not found
$firstname = isset($_POST['firstname']) ? trim($_POST['firstname']) : '';
$lastname = isset($_POST['lastname']) ? trim($_POST['lastname']) : '';
// prepare our data for safe sql use
$firstname = mysql_real_escape_string($firstname);
$lastname = mysql_real_escape_string($lastname);
// write out a query that we can see a little more plainly ...
$sql =
"UPDATE persons SET
fn = '{$firstname}',
ln = '{$lastname}'
WHERE ..."
;