[ת]PHP SQL ×¢Èë¹¥»÷µÄ¼¼ÊõʵÏÖÒÔ¼°Ô¤·À°ì·¨(2)
INSERT INTO tbl_user SET uid="1"; SELECT * FROM tbl_user WHERE uid="1";ÔÚ×îÐ嵀 MYSQL 5.x ÖУ¬ÉÏÃæµÄÓï¾ä²»ÊǺϷ¨µÄ£¬±ØÐëд³ÉÕâÑù£º
INSERT INTO tbl_user SET uid=1; SELECT * FROM tbl_user WHERE uid=1;ÕâÑùÎÒÈÏΪÊÇÕýÈ·µÄ¡£ÒòΪ×÷Ϊ¿ª·¢Õߣ¬ÏòÊý¾Ý¿âÌá½»ÕýÈ·µÄ·ûºÏ¹æÔòµÄÊý¾ÝÀàÐÍ£¬ÕâÊÇ×î»ù±¾µÄÒªÇó¡£
¡¡¡¡ÄÇô¹¥»÷ÕßÔÚ magic_quotes_gpc = On ʱ£¬ËûÃÇÔõô¹¥»÷ÄØ£¿ºÜ¼òµ¥£¬¾ÍÊǶÔÊýÖµÐ͵Ä×ֶνøÐÐ SQL ×¢Èë¡£ÒÔÏÂÁÐµÄ php ½Å±¾ÎªÀý£º
<? if ( isset($_POST["f_login"] ) ) { // Á¬½ÓÊý¾Ý¿â... // ...´úÂëÂÔ... // ¼ì²éÓû§ÊÇ·ñ´æÔÚ $t_strUid = $_POST["f_uid"]; $t_strPwd = $_POST["f_pwd"]; $t_strSQL = "SELECT * FROM tbl_users WHERE uid=$t_strUid AND password = '$t_strPwd' LIMIT 0,1"; if ( $t_hRes = mysql_query($t_strSQL) ) { // ³É¹¦²éѯ֮ºóµÄ´¦Àí. ÂÔ... } } ?> <html><head><title>sample test</title></head> <body> <form method=post action=""> User ID: <input type="text" name="f_uid" size=30><br> Password: <input type=text name="f_pwd" size=30><br> <input type="submit" name="f_login" value="µÇ¼"> </form> </body>¡¡ÉÏÃæÕâ¶Î½Å±¾ÒªÇóÓû§ÊäÈë userid ºÍ password µÇÈë¡£Ò»¸öÕý³£µÄÓï¾ä£¬Óû§ÊäÈë 1001ºÍabc123£¬Ìá½»µÄ sql Óï¾äÈçÏ£º
SELECT * FROM tbl_users WHERE userid=1001 AND password = 'abc123' LIMIT 0,1Èç¹û¹¥»÷ÕßÔÚ userid ´¦£¬ÊäÈ룺1001 OR 1 =1 #£¬Ôò×¢ÈëµÄsqlÓï¾äÈçÏ£º
SELECT * FROM tbl_users WHERE userid=1001 OR 1 =1 # AND password = 'abc123' LIMIT 0,1¹¥»÷Õß´ïµ½ÁËÄ¿µÄ¡£
¡¡Èý. ÈçºÎ·ÀÖ¹ PHP SQL ×¢Èë¹¥»÷
¡¡¡¡ÈçºÎ·ÀÖ¹ php sql ×¢Èë¹¥»÷£¿ÎÒÈÏΪ×îÖØÒªµÄÒ»µã£¬¾ÍÊÇÒª¶ÔÊý¾ÝÀàÐͽøÐмì²éºÍתÒå¡£×ܽáµÄ¼¸µã¹æÔòÈçÏ£º
- php.ini ÖÐµÄ display_errors Ñ¡ÏӦ¸ÃÉèΪ¡¡display_errors = off¡£ÕâÑù php ½Å±¾³ö´íÖ®ºó£¬²»»áÔÚ web Ò³ÃæÊä³ö´íÎó£¬ÒÔÃâÈù¥»÷Õß·ÖÎö³öÓÐ×÷µÄÐÅÏ¢¡£
- µ÷Óà mysql_query µÈ mysql º¯Êýʱ£¬Ç°ÃæÓ¦¸Ã¼ÓÉÏ @£¬¼´ @mysql_query(...)£¬ÕâÑù mysql ´íÎ󲻻ᱻÊä³ö¡£Í¬ÀíÒÔÃâÈù¥»÷Õß·ÖÎö³öÓÐÓõÄÐÅÏ¢¡£ÁíÍ⣬ÓÐЩ³ÌÐòÔ±ÔÚ×ö¿ª·¢Ê±£¬µ± mysql_query³ö´íʱ£¬Ï°¹ßÊä³ö´íÎóÒÔ¼° sql Óï¾ä£¬ÀýÈ磺
ÍƼöÐÅÏ¢
- ¡¾ÊÓƵ²¥·Å¡¿JplayerÊÓƵ²¥·ÅÆ÷µÄʹÓÃ
- memcacheÄÚ´æÔÀí
- Memcache¼¼Êõ·ÖÏí£º½éÉÜ¡¢Ê¹Óᢴ洢¡¢Ëã·¨¡¢ÓÅ»¯....
- php³£ÓÃÕýÔò±í´ïʽ
- phpÐÔÄܼà²âÄ£¿éXHProf
- ÈÃCI¿ò¼ÜÖ§³Öservice²ã
- ʹÓÃPHPÉú³É´øLOGOµÄ¸öÐÔ»¯¶þάÂëͼÏñ
- ¹ØÓÚCodeIgniterÄã¿ÉÄܲ»ÖªµÀµÄ5¸ö֪ʶµã
- Memcache ºÁÃ뼶³¬Ê±¼°ÆäËû³£¼ûÎÊÌâ»ã×Ü
- [PHP±Ê¼Ç]PHPQueryÒ»¸ö´¦ÀíDOMµÄÀûÆ÷
ÈÈÃÅÐÅÏ¢
- nohup: redirecting stderr to stdou....
- ʹÓÃlog_formatΪNginx·þÎñÆ÷ÉèÖøüÏêϸµÄÈÕÖ¾¸ñʽ
- jquery easyUI--dataGrid-Json
- [Ô´´]·ÂGoogle Reader¡¢ÐÂÀË΢²©¡¢ÌÚѶ΢²©µ....
- ÀûÓÃKeepalived+mysql¹¹½¨¸ß¿ÉÓÃMySQLË«Ö÷×Ô¶....
- Nginx+keepalivedʵÏÖ¸ºÔؾùºâºÍË«»úÈȱ¸¸ß¿ÉÓÃ
- jqueryʵÏÖÒ³Ãæ¼ÓÔؽø¶ÈÌõ
- Rolling cURL: PHP²¢·¢×î¼Ñʵ¼ù
- codeigniter ·ÓÉÖÕ¼«ÓÅ»¯(url rewrite)
- linuxÏÂÉèÖÃsshÎÞÃÜÂëµÇ¼
×î½ü¸üÐÂ
- PHP»ñÈ¡Óû§µÄÕæʵIP£¬²¢ÅжÏÊÇ·ñÄÚÍøIP
- PHP ´íÎóÈÕÖ¾ error_log
- ÀûÓÃbigpipe»úÖÆʵÏÖÒ³ÃæÄ£¿éµÄÒì²½äÖȾ chunked¼¼Êõ
- php¿ØÖÆÎļþÏÂÔØËÙ¶È
- js + php ¶ÁÈ¡¡¢²¥·ÅÊÓƵÁ÷ ¼æÈÝfirefox£¬c....
- ¡¾ÊÓƵ²¥·Å¡¿JplayerÊÓƵ²¥·ÅÆ÷µÄʹÓÃ
- UNICODE Óë UTF-8 µÄ¹Øϵ
- memcacheÄÚ´æÔÀí
- Memcache¼¼Êõ·ÖÏí£º½éÉÜ¡¢Ê¹Óᢴ洢¡¢Ëã·¨¡¢ÓÅ»¯....
- phpʹÓÃmb_detect_encoding¼ì²â×Ö·û´®±àÂë
ÆÀÂÛ