dongwu3596 2019-01-27 04:40
浏览 36

函数wpdb-> query是否自动清理?

I am creating a plugin that uses SQL queries in it. I would like to know if this function is sanitized?

I have already tried using wpdb->prepare and get_result. neither of those like my query at all, but I may be missing something.

global $wpdb;

$table_name = $wpdb->prefix . 'TableName';

$result = $wpdb->query("INSERT INTO $table_name(foo, bar, foobar, fa, baar, fabaar, origin)
        VALUES ('" . $_POST['foo'] . "', 
        '" . $_POST['bar'] . "', 
        '" . $_POST['foobar'] . "', 
        '" . $_POST['fa'] . "',
        '" . $_POST['baar'] . "',
        '" . $_POST['fabaar'] . "',
        '" . $_POST['origin'] . "');");

echo 'Posting was a success!';
die;

I want this to run the query in a sanitized and safe way.

  • 写回答

0条回答 默认 最新

    报告相同问题?

    悬赏问题

    • ¥15 请问paddlehub能支持移动端开发吗?在Android studio上该如何部署?
    • ¥170 如图所示配置eNSP
    • ¥20 docker里部署springboot项目,访问不到扬声器
    • ¥15 netty整合springboot之后自动重连失效
    • ¥15 悬赏!微信开发者工具报错,求帮改
    • ¥20 wireshark抓不到vlan
    • ¥20 关于#stm32#的问题:需要指导自动酸碱滴定仪的原理图程序代码及仿真
    • ¥20 设计一款异域新娘的视频相亲软件需要哪些技术支持
    • ¥15 stata安慰剂检验作图但是真实值不出现在图上
    • ¥15 c程序不知道为什么得不到结果