I want to execute the following query:
uvalue = EditText( some user value ); p_query = "select * from mytable where name_field = '" + uvalue + "'" ; mDb.rawQuery( p_query, null );
if the user enters a single quote in his input, it is reset. If you change it to:
p_query = "select * from mytable where name_field = \"" + uvalue + "\"" ;
it crashes if the user enters a double quote in his input. and, of course, they could always enter single and double quotes.
android sqlite
miannelle Aug 18 '09 at 20:05 2009-08-18 20:05
source share