Hopefully someone can help me out before I lose my hair
I've got this insert string and unfortunately when a " is used in the newtitle it stops the query then.
For example if you put asd"fgh it'll only put asd into the database and ignore the rest.
Here is the query I'm using
Code:
$db->query_write("INSERT INTO " .TABLE_PREFIX. "title_wars
(
newtitle,
attacker,
victim,
attackerid,
victimid
) VALUES (
'". $db->escape_string($_POST['newtitle'])."',
'" . $db->escape_string($_POST['attacker']) . "',
'" . $db->escape_string($_POST['victim']) . "',
'" . $db->escape_string($vbulletin->userinfo['userid']) . "',
'" . $db->escape_string($_POST['victimid']) . "'
)");
Any ideas?