<?php
class Insert
{
var $_SQLStatement = "";
function Insert()
{
$sql_columns_use = array();
$sql_value_use = array();
array_pop($_POST);
foreach($_POST as $key => $value)
{
$value = trim($value);
if (is_numeric($value))
{
$sql_value_use[] = $value;
}
else
{
$sql_value_use[] = (get_magic_quotes_gpc()) ? "'".$value."'" : "'".addslashes($value)."'";
}
$sql_columns_use[] = $key;
}
$this->_SQLStatement = "INSERT INTO ".$tbl." (".implode(",",$sql_columns_use).") VALUES (".implode(",",$sql_value_use).")";
}
}//
?>
<?php
$obj = new Insert();
if(isset($_POST['name']))
{
var_dump($obj->SQLStatement);
}
?>
<form action="<?php echo $_SERVER['PHP_SELF']; ?>" method="post" name="myForm">
Name: <input name="name" type="text"></p>
Age: <input name="email" type="text"></p>
Phone Number: <input name="tel" type="text"></p>
<input name="action" type="submit" value="AddToDB"></p>
</form>