Escape double quotes in SQL 2005/2008

后端 未结 8 2073
渐次进展
渐次进展 2020-12-21 00:41

I have an international company that has recently been added, which is named \"BLA \"BLAHBLAH\" Ltd. (The double quotes are part of the name. )

Whenever a user tries

8条回答
  •  醉话见心
    2020-12-21 00:57

    Use a parameterized query and all your quoting woes will be gone.

    Edit: If you're not letting them enter more than one word in the CONTAINS, sanitize the parameter by removing the quotes. Sanitizing the input by removing the quotes may work anyhow, regardless of the multi-word search.

提交回复
热议问题