doupike2351 2015-05-31 06:23
浏览 41
已采纳

PHP PDO仅在源中显示从数据库查询代码

I'm using PDO to query some data from my database but I have a section with raw php code that doesn't show up, only in the source as if it's trying to run.

I have the slashes stripped and I have it echoed under pre/code tags so I'm wondering as to why it won't show on the page.

Database

id    name(VARCHAR)           code (LONGTEXT)
1         test         <?php echo /'hello world/'; ?>

PHP File

<?php
        try {
            $db = new PDO('mysql:host=localhost;dbname=$dbname;charset=utf8', '$username', '$password');
            $db->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION);
            $db->setAttribute(PDO::ATTR_EMULATE_PREPARES, false);

            $stmt = $db->prepare('SELECT name, codeOne FROM table_one WHERE id = :id');

            $stmt->bindParam(':id', '1');

            $stmt->execute();

            while ($row = $stmt->fetch(PDO::FETCH_ASSOC)) {
                    echo $row['name'] . '<pre><code>'. stripslashes($row['codeOne']) .'</code></pre>';
                }

        } catch(PDOException $e) {
            return $e->getMessage();
        };
    ?>

What Everyone Sees

test

View Source

test<pre><code><?php echo "Hello";?></code></pre>

展开全部

  • 写回答

1条回答 默认 最新

  • douxie9471 2015-05-31 06:28
    关注

    Well just use htmlspecialchars() to encode your string, e.g.

    echo htmlspecialchars('<?php echo "Hello";?>');
    

    What you see:

    <?php echo "Hello";?>
    

    Source code:

    &lt;?php echo &quot;Hello&quot;;?&gt;
    

    OR if you want to be really fancy you could use: highlight_string(), which also gives some nice color to your string:

    echo highlight_string('<?php echo "Hello";?>', TRUE);
    
    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论
编辑
预览

报告相同问题?

手机看
程序员都在用的中文IT技术交流社区

程序员都在用的中文IT技术交流社区

专业的中文 IT 技术社区,与千万技术人共成长

专业的中文 IT 技术社区,与千万技术人共成长

关注【CSDN】视频号,行业资讯、技术分享精彩不断,直播好礼送不停!

关注【CSDN】视频号,行业资讯、技术分享精彩不断,直播好礼送不停!

客服 返回
顶部