dongtang1944 2015-12-14 15:24
浏览 40
已采纳

带引号的PDO查询[重复]

This question already has an answer here:

I developping an admin panel, i have the PDO stuff for my db. Here is my post PHP for update texte in my website:

$text1= $_POST['text1'];
$text2= $_POST['text2'];
$query = $con->prepare("UPDATE `home` SET text1='$text1', text2='$text2' WHERE id=1;");
$query->execute();
if ($query) {
    echo 'good';....}

If i write quotes it's say my sql query is not good. I have tried quote() and prepare() but don't work too. How can i do for use quote in my input ?

PS: In all my query i have specials char like: é à ü ù and other (i'm french)

</div>
  • 写回答

1条回答 默认 最新

  • dongyong3554 2015-12-14 15:28
    关注

    Use bound parameters:

    $text1= $_POST['text1'];
    $text2= $_POST['text2'];
    $query = $con->prepare("UPDATE `home` SET text1=?, text2=? WHERE id=1;");
    $query->execute([$text1, $text2]);
    
    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 uniapp uview http 如何实现统一的请求异常信息提示?
  • ¥15 有了解d3和topogram.js库的吗?有偿请教
  • ¥100 任意维数的K均值聚类
  • ¥15 stamps做sbas-insar,时序沉降图怎么画
  • ¥15 买了个传感器,根据商家发的代码和步骤使用但是代码报错了不会改,有没有人可以看看
  • ¥15 关于#Java#的问题,如何解决?
  • ¥15 加热介质是液体,换热器壳侧导热系数和总的导热系数怎么算
  • ¥100 嵌入式系统基于PIC16F882和热敏电阻的数字温度计
  • ¥20 BAPI_PR_CHANGE how to add account assignment information for service line
  • ¥500 火焰左右视图、视差(基于双目相机)