I'd do it like this:
PHP Code:
$judgeFirstName = mysql_real_escape_string($_POST['judgeFirstName']);
$judgeLastName = mysql_real_escape_string($_POST['judgeLastName']);
$judgeCountry = mysql_real_escape_string($_POST['judgeCountry']);
$judgeEmail = mysql_real_escape_string($_POST['judgeEmail']);
$judgeCKCnumber = mysql_real_escape_string($_POST['judgeCKCnumber']);
$judgeCDJAnumber = mysql_real_escape_string($_POST['judgeCDJAnumber']);
$judgeAKCnumber = mysql_real_escape_string($_POST['judgeAKCnumber']);
$sql=sprintf('
INSERT INTO judgegallery (
firstName
, lastName
, country
, emailaddy
, ckcNumber
, akcNumber
, cdjaNumber
) VALUES (
"%s", "%s", "%s", "%s", "%s", "%s", "%s"
)',
$judgeFirstName,
$judgeLastName,
$judgeCountry,
$judgeEmail,
$judgeCKCnumber,
$judgeCDJAnumber,
$judgeAKCnumber
);
if (!mysql_query($sql,$con))
{
die('Error: ' . mysql_error());
}
You also need to apply mysql_real_escape_string on int's. It's to prevent SQL injection, and than can just as easily happen with ints as with strings.
Bookmarks