doucang8303 2014-01-07 19:55
浏览 72
已采纳

两个mysql查询之一不显示结果

I'm learning PHP and I need to select some media from database by id or slug. Can I ask you why this code works fine:

index.php?id=1

if( isset( $_GET['id'] ) ) {
    $id = $_GET['id'];
    $query = mysql_query("SELECT * FROM media WHERE id = $id");

    while($row=mysql_fetch_array($query)) {
        echo $row['slug'];
    }
}

And this not?

index.php?slug=first-post-slug

if( isset( $_GET['slug'] ) ) {
    $slug = $_GET['slug'];
    $query = mysql_query("SELECT * FROM media WHERE slug = $slug");

    while($row=mysql_fetch_array($query)) {
        echo $row['id'];
    }
}

The second piece of code does not return anything, and the first piece of code returns proper slug ;/

  • 写回答

2条回答 默认 最新

  • duanfu1945 2014-01-07 19:56
    关注

    You should escape the variable:

    $slug = mysql_real_escape_string($_GET['slug']);
    $query = mysql_query("SELECT * FROM media WHERE slug = '". $slug ."'");
    

    And also you should cast id to int:

    $id = (int) $_GET['id'];
    
    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论
查看更多回答(1条)

报告相同问题?