Im trying to add this code
$variable = htmlentities($variabletoconvert, ENT_QUOTES);
to this:
<form action="?id=t_nimda" method="post">
<p>Title<br>
<input name="frmtitle" type="text" value="Title">
<br>
Date<br>
<input name="frmdate" type="text" value="<?php print date("F j Y"); ?>">
<br>
Avatar URL:<br>
<input name="frmavatar" type="text" class="emailform" value="http://www.projectrage.com/icons/" size="23">
<br>
Author:<br>
<input name="frmuser" type="text" value="name" size="23">
<br>
Author Email:<br>
<input name="frmemail" type="text" value="rage@projectrage.com" size="23">
<br>
Description:<br>
<textarea name="frmdescription" cols="15" rows="2"></textarea>
<br>
Category:<br>
<select name="frmcategory">
<option>HTML</option>
<option>Photoshop</option>
<option>PHP</option>
<option>CSS</option>
</select>
<br>Valid BB Code: [quote][/quote]
<br>Tutorial Message:<br>
<textarea name="frmmessage" cols="40" rows="10"></textarea>
<br>Password:
<input name='password' type='password'><br>
<input name="submit" type="submit"></p>
</form>
<?php
$password="qwerty";
if ($_POST["password"]==$password){
if (isset($_POST['submit'])) {
include("dbconnect.php");
$Title = addslashes(strip_tags($_POST['frmtitle']));
$Avatar = addslashes(strip_tags($_POST['frmavatar']));
$User = addslashes(strip_tags($_POST['frmuser']));
$Email = addslashes(strip_tags($_POST['frmemail']));
$Category = addslashes(strip_tags($_POST['frmcategory']));
$Message = $_POST['frmmessage'];
$Description = addslashes($_POST['frmdescription']);
$date = addslashes(strip_tags($_POST['frmdate']));
$sql = "INSERT INTO $table SET title='$Title', avatar='$Avatar',
user='$User', email = '$Email', category='$Category', message='$Message', description='$Description', date='$date'";
if (mysql_query($sql)) {
echo("Your tutoral has been added.");
} else {
echo("Error adding entry: " . mysql_error() . "");
}
}
}
?>
ive tried many different ways, and none seemed to work!
