dongzhang5787 2016-03-31 23:03
浏览 29
已采纳

使用PHP中的$ _request变量进行数据库更新

I'm trying to update the user password in this code. I know it is not reliable since it does not has SQL injection prevention feature, I'm just trying to learn here. anyway, using $_request variable in my code does not work with the database query, it works when I want to display the variable with echo.

PHP code:

$newPassword=$_POST['newPassword'];
$confirmPassword=$_POST['confirmPassword'];
$userID1=$_REQUEST['ID'];
$code=$_GET['$code'];
echo "<h1>Hello " . $userID1 . "</h1>";
if (isset($_GET['submit'])) 
{

    if($newPassword == $confirmPassword ){

            mysql_query("UPDATE facultymember SET password='$newPassword' WHERE ID='$userID1'");
            $message = "Your password has been updated.";
           } 
    else 
        {
        $message = "New password does not equal Confirm password";
        }
 }

HTML form:

<form name="frmChange" action='newpass.php' method="GET" onSubmit="return validatePassword()">
    <div style="color:red;" "class="message"><?php if(isset($message)) { echo $message; } ?></div>
  Enter a new password
      <input type="text" name="newPassword">
    Re-enter the new password
      <input type="text" name="confirmPassword">

    <input name="submit" type="submit" value="Save Changes">
</form>
  • 写回答

1条回答 默认 最新

  • duanhao7786 2016-03-31 23:07
    关注

    wrong object to get value , when you are submitting GET request method="GET"

    $newPassword=$_POST['newPassword'];
    $confirmPassword=$_POST['confirmPassword'];
    or
    $newPassword=$_GET['newPassword'];
    $confirmPassword=$_GET['confirmPassword'];
    

    and no ID param also attached

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 centos7.9 IPv6端口telnet和端口监控问题
  • ¥120 计算机网络的新校区组网设计
  • ¥20 完全没有学习过GAN,看了CSDN的一篇文章,里面有代码但是完全不知道如何操作
  • ¥15 使用ue5插件narrative时如何切换关卡也保存叙事任务记录
  • ¥20 海浪数据 南海地区海况数据,波浪数据
  • ¥20 软件测试决策法疑问求解答
  • ¥15 win11 23H2删除推荐的项目,支持注册表等
  • ¥15 matlab 用yalmip搭建模型,cplex求解,线性化处理的方法
  • ¥15 qt6.6.3 基于百度云的语音识别 不会改
  • ¥15 关于#目标检测#的问题:大概就是类似后台自动检测某下架商品的库存,在他监测到该商品上架并且可以购买的瞬间点击立即购买下单