douluokuang7184 2014-11-07 18:19
浏览 74
已采纳

PHP + MySQL“INSERT INTO”错误

I have this sql string:

$sql = "INSERT INTO foto (id, nome, check)
            VALUES ('', '" . md5($file) . '.' .$Type. "', '" . md5($file2) . '.' .$Type2. "')";

but it returns this error:

INSERT INTO foto (nome, check) VALUES ('57f030f902b9fbd6907d1af52ec2a1ba.jpg', '8c96b1254a72dbd080a9b79a9a224865.jpg')
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'check) VALUES ('57f030f902b9fbd6907d1af52ec2a1ba.jpg', '8c96b1254a72dbd080a9' at line 1

'

md5($file) + $Type = 57f030f902b9fbd6907d1af52ec2a1ba.jpg
md5($file2) + $Type2 = 8c96b1254a72dbd080a9b79a9a224865.jpg

What's the problem? How can I solve it?

  • 写回答

1条回答 默认 最新

  • doudi2520 2014-11-07 18:21
    关注

    check is a MySQL reserved word

    which requires it to be wrapped in backticks, or rename it to checks for example in your table.

    $sql = "INSERT INTO foto (id, nome, `check`)
    

    if you want to rename it, then just do

    $sql = "INSERT INTO foto (id, nome, checks)
    

    which won't throw an error; the option is yours.


    Notice where the error starts and points to:

    >...MySQL server version for the right syntax to use near 'check
                                                              ^ starts there
    

    Plus, once you've fixed that, your code would still be open to SQL injection.
    Use mysqli with prepared statements, or PDO with prepared statements, they're much safer.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 R语言爬虫的时候元素和园代码不一样怎么解决呀
  • ¥15 VS2022多项目启动有问题
  • ¥15 SQL删除添加数据后序号不连续问题。
  • ¥15 首次运行OmniEvent运行报错
  • ¥15 有没有人知道这个问题怎么解决
  • ¥15 comsol电力电缆载流量仿真
  • ¥15 webSocket可以接TCP socket接口吗
  • ¥60 mpi并行出错,CFD++计算
  • ¥15 c#:vsto,powerpoint的外接程序中换主题颜色
  • ¥15 状态机/汽车转向灯/Sateflow