Re: Use the User Input Critia as part of Query! (Mysql)

From: Date: Mon, 03 Sep 2001 17:37:16 +0000
Subject: Re: Use the User Input Critia as part of Query! (Mysql)
References: 1 2  Groups: php.db 
Request: Send a blank email to php-db+get-12123@lists.php.net to get a copy of this message
"Jason Wong" <phplist@gremlins.com.hk> wrote in message news:021701c13489$245b1f40$0400000a@gremlins.com.hk... > ----- Original Message ----- > From: Jack <jack@nedcor.com> > To: <php-db@lists.php.net>; <php-windows@lists.php.net> > Sent: Monday, September 03, 2001 10:35 PM > Subject: [PHP-DB] Use the User Input Critia as part of Query! (Mysql) > > > $query="select name,department,Leave_From,Leave_To, > > Leave_Total,Reason from leaverequest where > > Staff_Number="<?print("$StaffNum");?>" and authorized > > is null"; > > > Try something like: > $query="select name,department,Leave_From,Leave_To, > Leave_Total,Reason from leaverequest where Staff_Number > ='$StaffNum' and authorized is null"; Also, for security, you would be wise to cast $StaffNum to int before using it: $StaffNum = (int) $StaffNum; $query = "SELECT " ."name,department,Leave_From,Leave_To," ."Leave_Total,Reason " ."FROM leaverequest " ."WHERE Staff_Number=$StaffNum " ."AND authorized IS NULL"; HTH

« previous php.db (#12123) next »