Re: UPDATE MySQL
| From: | Marco Tabini | Date: | Wed, 13 Nov 2002 22:18:18 +0000 |
| Subject: | Re: UPDATE MySQL | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-124329@lists.php.net to get a copy of this message | ||
I can see two things that are not correct in the statement:
First, the date you're setting is in UNIX format--but MySQL wont' like
that. You need to use FROM_UNIXTIME.
Second, the username is a string (I guess), but it's not within
quotation marks.
$myquery = "UPDATE penpals SET lastaccess=FROM_UNIXTIME($lastaccessdate)
WHERE ID='$myuserid'";
Two notes:
The MySQL extension does not normally print out errors. You need to
explicity call mysql_error() to do that. In this case, you can add it
after the call to mysql_query(), e.g.:
die (mysql_error());
Also, you are passing HTTP data directly to MySQL. This can allow a
malicious user to insert potentially "evil" code in your call and cause
all sorts of damage. I suggest you consider filtering that information
using one of the many methods available.
Marco
--
------------
php|architect - The magazine for PHP Professionals
The first monthly worldwide magazine dedicated to PHP programmers
Come visit us at http://www.phparch.com!