douju6850 2016-01-31 19:27
浏览 25
已采纳

PHP文件上传名称到sql表

I am trying to allow for file upload and then writing the name of that file into a SQL table so it can be displayed. My form looks like this:

<form class="addProduct" name="addNewProduct" action="add_product.php" method="GET">
<div class="form-group">
<label for="productImgName">Image:</label>
<input type="file" id="productImgName" name="productImgName">
<p class="help-block">This will be re-sized</p>
</div>
</form>

And then the PHP file is:

$target = "images/";
$target = $target . basename( $_FILES['productImgName']['name']);

$Filename=basename( $_FILES['productImgName']['name']);


 if(move_uploaded_file($_FILES['productImgName']['tmp_name'], $target)) {
echo "The file ". basename( $_FILES['productImgName']['name']). " has been uploaded, and your information has been added to the directory";

mysqli_query("INSERT INTO products (productImgName)
VALUES ('$Filename')") ;
} else {
//Gives and error if its not
echo "Sorry, there was a problem uploading your file.";
}

It won't upload and Im not sure why.

  • 写回答

1条回答 默认 最新

  • dongliling6336 2016-01-31 19:32
    关注

    There are two issues with your form element:

    • You cannot use the GET method to upload files
    • You need to specify the enctype attribute

      <form class="addProduct" name="addNewProduct" action="add_product.php" method="POST" enctype="multipart/form-data">
      

    Documentation.

    Also note that the filename is user input and should be treated as such. Sanitize it before adding it to your query or use prepared statements.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 想问一下树莓派接上显示屏后出现如图所示画面,是什么问题导致的
  • ¥100 嵌入式系统基于PIC16F882和热敏电阻的数字温度计
  • ¥15 cmd cl 0x000007b
  • ¥20 BAPI_PR_CHANGE how to add account assignment information for service line
  • ¥500 火焰左右视图、视差(基于双目相机)
  • ¥100 set_link_state
  • ¥15 虚幻5 UE美术毛发渲染
  • ¥15 CVRP 图论 物流运输优化
  • ¥15 Tableau online 嵌入ppt失败
  • ¥100 支付宝网页转账系统不识别账号