escaping string quotes in sql insert query

Viewed 157

I am trying to allow people to input descriptions to a certain product, and this will be done through a dashboard, so I will not know in advance what a user will be inserting. however, It is required that the user will be able to insert a description like: this item is 10" wide. however, in sql (db2), it sees that as a string ending delimiter, which makes sense, but I cannot seem to find a way around this.

sometimes people may put item1 is 10" wide and 3' tall, again with multiple quotes in there where db2 would see that as an issue.

my query for the insert is standard, I've included it below"

var submitEdit =
      "UPDATE PRODUCTS SET (ITEM, PRICE, SIZES, DESCRIPTION, IMAGE) = ('" +
      req.query.item +
      "', '" +
      req.query.price +
      "', '" +
      size +
      "', '" +
      req.query.description +
      "', '" +
      image_url + "') WHERE ITEM = '" +
      req.query.ogItem +
      "'";

also, I know this query is easy access to sql injection, so I will be changing it eventually, but I would like to figure this out first lol!

thanks for the help in advance :)

0 Answers
Related