donglue1886 2014-09-26 02:03
浏览 35
已采纳

使用PHP将数据输入MySQL数据库时出现问题

I have been checking my syntax all night yet I can't seem to see what is wrong. I'm relatively new to all this and would appreciate nay help that may be provided. The error I'm getting is

"You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''ID','Name','Option','Sides') VALUES(NULL,'Denise','Chicken','Mashed Potat' at line 1"

My code is below:

<?php
include 'connect.php';

$name = $_POST['inputName'];
$opt = $_POST['inputOption'];
$side = $_POST['inputSides'];

if(!$_POST['Submit']) {
    echo "Please fill out the form.";
    header('Location: index.php');
} else {
    mysql_query("INSERT INTO people ('ID','Name','Option','Sides')
                VALUES(NULL,'$name','$opt','$side')") or die(mysql_error());
    echo "User has been added.";
    header('Location: index.php');
    }
?>
  • 写回答

1条回答 默认 最新

  • dongyao8698 2014-09-26 02:04
    关注

    You're using the wrong identifiers for your columns:

    ('ID','Name','Option','Sides')
    

    Either remove the quotes or wrap them in backticks.

    (`ID`,`Name`,`Option`,`Sides`)
    

    Plus, your present code is open to SQL injection.
    Use mysqli with prepared statements, or PDO with prepared statements, they're much safer.

    Another thing; should you want to be entering apostrophes, use stripslashes() including mysql_real_escape_string(). The occasion may very well present itself; an insight.

    • Otherwise, SQL will throw another error.
    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 mmocr的训练错误,结果全为0
  • ¥15 python的qt5界面
  • ¥15 无线电能传输系统MATLAB仿真问题
  • ¥50 如何用脚本实现输入法的热键设置
  • ¥20 我想使用一些网络协议或者部分协议也行,主要想实现类似于traceroute的一定步长内的路由拓扑功能
  • ¥30 深度学习,前后端连接
  • ¥15 孟德尔随机化结果不一致
  • ¥15 apm2.8飞控罗盘bad health,加速度计校准失败
  • ¥15 求解O-S方程的特征值问题给出边界层布拉休斯平行流的中性曲线
  • ¥15 谁有desed数据集呀