duanhongyi2964 2014-03-16 15:20 采纳率: 100%
浏览 40
已采纳

将php表单插入mysql数据库时如何修复错误

I'm trying to save data from a form into a mysql database. I can connect to the database but for some reason I can't get it to insert the data into the database. I have a feeling it might just be a syntax error I'm not seeing.

Any help would be much appreciated.

PHP

// Get values from form 
 $Nombre=$_POST['Nombre'];
 $Email=$_POST['Email'];
 $Telefono=$_POST['Telefono'];

// Insert data into mysql 
$sql="INSERT INTO $leads(Nombre, Email, Telefono)VALUES('$Nombre','$Email','$Telefono')";
$result=mysql_query($sql);

// if successfully insert data into database, displays message "Successful". 
if($result){
echo "Successful";
echo "<BR>";
}

else {
echo "ERROR";
}

HTML

  <form action="leads.php" method="POST">
       <input placeholder="Nombre" type="text" name="Nombre" maxlength="40"/>
       <input placeholder="Email" type="text" name="Email" maxlength="100"/>
       <input placeholder="Teléfono" type="text" name="Telefono" maxlength="9" pattern=".{8,}"    required title="8 numeros mínimo"/>
       <button class="btn-cita" name="cita">Hacer Cita</button>
  </form>
  • 写回答

1条回答 默认 最新

  • douna3367 2014-03-16 15:21
    关注

    Yes, you do. You are vulnerable to SQL injection attacks, and are using undefined variables in your query:

    $sql="INSERT INTO $leads(Nombre, Email, Telefono)VALUES('$Nombre','$Email','$Telefono')";
                      ^^^^^^---undefined
    

    Producing a query something like

    INSERT INTO (Nombre, etc...
    
    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 安卓adb backup备份应用数据失败
  • ¥15 eclipse运行项目时遇到的问题
  • ¥15 关于#c##的问题:最近需要用CAT工具Trados进行一些开发
  • ¥15 南大pa1 小游戏没有界面,并且报了如下错误,尝试过换显卡驱动,但是好像不行
  • ¥15 没有证书,nginx怎么反向代理到只能接受https的公网网站
  • ¥50 成都蓉城足球俱乐部小程序抢票
  • ¥15 yolov7训练自己的数据集
  • ¥15 esp8266与51单片机连接问题(标签-单片机|关键词-串口)(相关搜索:51单片机|单片机|测试代码)
  • ¥15 电力市场出清matlab yalmip kkt 双层优化问题
  • ¥30 ros小车路径规划实现不了,如何解决?(操作系统-ubuntu)