dongxian5735 2016-01-14 10:39
浏览 32
已采纳

通过$ _GET [duplicate]传递变量时SQL中的错误查询

This question already has an answer here:

Here is the query:

$table = $_GET['type'];
$q="DELETE FROM '$table' WHERE cont_id='".$_GET['where']."'";

I also tried removing the single/double quotes on the $_GET part, but didn't work. I'm printing the values of my variables before executing the query and they are right so I don't think that's the problem.

Any ideas?

</div>
  • 写回答

3条回答 默认 最新

  • dongzhan3937 2016-01-14 10:41
    关注

    Database table names should not be enclosed with single quotes.

    Corrected SQL:

    $q="DELETE FROM $table WHERE cont_id='".$_GET['where']."'";
    

    Tables and field names can be enclosed with backticks (`) to avoid clashes with

    MySQL reserved keywords.

    In that case, corrected SQL should be:

    $q="DELETE FROM `$table` WHERE `cont_id` = '".$_GET['where']."'";
    

    Also, do not trust input from user.

    This can cause security vulnerability.

    use mysqli_real_escape_string() for $_GET['where']

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论
查看更多回答(2条)

报告相同问题?

悬赏问题

  • ¥15 使用ue5插件narrative时如何切换关卡也保存叙事任务记录
  • ¥20 软件测试决策法疑问求解答
  • ¥15 win11 23H2删除推荐的项目,支持注册表等
  • ¥15 matlab 用yalmip搭建模型,cplex求解,线性化处理的方法
  • ¥15 qt6.6.3 基于百度云的语音识别 不会改
  • ¥15 关于#目标检测#的问题:大概就是类似后台自动检测某下架商品的库存,在他监测到该商品上架并且可以购买的瞬间点击立即购买下单
  • ¥15 神经网络怎么把隐含层变量融合到损失函数中?
  • ¥15 lingo18勾选global solver求解使用的算法
  • ¥15 全部备份安卓app数据包括密码,可以复制到另一手机上运行
  • ¥20 测距传感器数据手册i2c