better yet....this is the whole snippet:
$editFormAction = $_SERVER['PHP_SELF'];
if (isset($_SERVER['QUERY_STRING'])) {
$editFormAction .= "?" . htmlentities($_SERVER['QUERY_STRING']);
}
if ((isset($_POST["MM_insert"])) && ($_POST["MM_insert"] == "form1")) {
$insertSQL = sprintf("INSERT INTO main (dnum, dvnum, drev, dtype, ddesc, dloc, dvend, dsys, dssys, dkey) VALUES (%s, %s, %s, %s, %s, %s, %s, %s, %s, %s)",
GetSQLValueString($_POST['dnum'], "text"),
GetSQLValueString($_POST['dvnum'], "text"),
GetSQLValueString($_POST['drev'], "text"),
GetSQLValueString($_POST['dtype'], "text"),
GetSQLValueString($_POST['ddesc'], "text"),
GetSQLValueString($_POST['dloc'], "text"),
GetSQLValueString($_POST['dvend'], "text"),
GetSQLValueString($_POST['dsys'], "text"),
GetSQLValueString($_POST['dssys'], "text"),
GetSQLValueString($_POST['dkey'], "text"));
mysql_select_db($database_BirchTest, $BirchTest);
$Result1 = mysql_query($insertSQL, $BirchTest) or die(mysql_error());
$insertGoTo = "AddConfirm.php";
if (isset($_SERVER['QUERY_STRING'])) {
$insertGoTo .= (strpos($insertGoTo, '?')) ? "&" : "?";
$insertGoTo .= $_SERVER['QUERY_STRING'];
}
header(sprintf("Location: %s", $insertGoTo));