function tool_preference($csv_name, $table_name, $the_session_id) { global $mysqli; if(isset($_POST['select_name_0'])&&$_POST['select_name_0']=="") { header("Location:csv_upload_error.php"); exit(); return FALSE; } else { $insert_statement=""; $handle=fopen("$csv_name", "r"); $counter=0; while ((!$row=fgetcsv($handle))== false) { $counter++; if($counter>1) //omit the column headings { //here's where you need to craft your query $insert_statement = 'insert into '.$table_name.'('; for($i=0; $i<=$_POST['column_count']; $i++) { if (isset($_POST['select_name_'.$i.'']) && $_POST['select_name_'.$i.'']=="") { header("location:csv_upload_error.php"); exit(); } else { $insert_statement.=$_POST['select_name_'.$i.'']; if($i<$_POST['column_count']) { $insert_statement.=','; } else { $insert_statement.=', session_id)'; } } } $insert_statement.=' VALUES ('; for($i=0; $i<=$_POST['column_count']; $i++) { $the_row[$i]=$mysqli->real_escape_string($row[$i]); $insert_statement .='\''; $insert_statement .=$_POST['column_'.$i.'']; $insert_statement .='\''; if($i<$_POST['column_count']) { $insert_statement.=','; } else { $insert_statement .=', \''; $insert_statement .="$the_session_id"; $insert_statement .='\''; $insert_statement .=')'; } } //echo $insert_statement; //$query=$mysqli->query($insert_statement); } } } return $insert_statement; }