参见英文答案 > real escape string and PDO 3个
在我的代码中我试图将MysqL_real_escape_string转换为PDO语句.有人有关于如何在PDO中编写MysqL_real_escape_string的提示吗?
我在两行中使用MysqL_real_escape_string:
$userName = MysqL_real_escape_string($_ POST [‘username’]);
$password = sha1(MysqL_real_escape_string($_ POST [‘password’]));
PHP
ob_start();
session_start();
include("../database/db.PHP");
$userName = MysqL_real_escape_string($_POST['username']);
$password = sha1(MysqL_real_escape_string($_POST['password']));
echo "
MysqL_query($query);
// $rows = $res->fetch(PDO::FETCH_ASSOC);
$rows = MysqL_fetch_assoc($res);
echo "
MysqL_num_rows($res) . "
prepare("select" *="" from="" tbladmin="" where="" admin_usr_name="$userName" and="" admin_pwd="$password" ");="" $find->execute();="" if="" ($find->fetchcolumn()="" >="" 0)="" {="" echo="" 'you="" made="" it,welcome';="" $_session['username']="$rows['admin_usr_name'];" $_session['admin_id']="$rows['admin_id'];" header("location:="" ..="" pages="" content.PHP");
prepare("select" *="" from="" tbladmin="" where="" admin_usr_name="$userName" and="" admin_pwd="$password" ");="" $find->execute();="" if="" ($find->fetchcolumn()="" >="" 0)="" {="" echo="" 'you="" made="" it,welcome';="" $_session['username']="$rows['admin_usr_name'];" $_session['admin_id']="$rows['admin_id'];" header("location:="" ..="" pages="" content.// }
prepare("select" *="" from="" tbladmin="" where="" admin_usr_name="$userName" and="" admin_pwd="$password" ");="" $find->execute();="" if="" ($find->fetchcolumn()="" >="" 0)="" {="" echo="" 'you="" made="" it,welcome';="" $_session['username']="$rows['admin_usr_name'];" $_session['admin_id']="$rows['admin_id'];" header("location:="" ..="" pages="" content.// else
prepare("select" *="" from="" tbladmin="" where="" admin_usr_name="$userName" and="" admin_pwd="$password" ");="" $find->execute();="" if="" ($find->fetchcolumn()="" >="" 0)="" {="" echo="" 'you="" made="" it,welcome';="" $_session['username']="$rows['admin_usr_name'];" $_session['admin_id']="$rows['admin_id'];" header("location:="" ..="" pages="" content.// {
prepare("select" *="" from="" tbladmin="" where="" admin_usr_name="$userName" and="" admin_pwd="$password" ");="" $find->execute();="" if="" ($find->fetchcolumn()="" >="" 0)="" {="" echo="" 'you="" made="" it,welcome';="" $_session['username']="$rows['admin_usr_name'];" $_session['admin_id']="$rows['admin_id'];" header("location:="" ..="" pages="" content.// echo 'Username and password dont match
PHP?loginerror=yes");
prepare("select" *="" from="" tbladmin="" where="" admin_usr_name="$userName" and="" admin_pwd="$password" ");="" $find->execute();="" if="" ($find->fetchcolumn()="" >="" 0)="" {="" echo="" 'you="" made="" it,welcome';="" $_session['username']="$rows['admin_usr_name'];" $_session['admin_id']="$rows['admin_id'];" header("location:="" ..="" pages="" content.// }
prepare("select" *="" from="" tbladmin="" where="" admin_usr_name="$userName" and="" admin_pwd="$password" ");="" $find->execute();="" if="" ($find->fetchcolumn()="" >="" 0)="" {="" echo="" 'you="" made="" it,welcome';="" $_session['username']="$rows['admin_usr_name'];" $_session['admin_id']="$rows['admin_id'];" header("location:="" ..="" pages="" content.
prepare("select" *="" from="" tbladmin="" where="" admin_usr_name="$userName" and="" admin_pwd="$password" ");="" $find->execute();="" if="" ($find->fetchcolumn()="" >="" 0)="" {="" echo="" 'you="" made="" it,welcome';="" $_session['username']="$rows['admin_usr_name'];" $_session['admin_id']="$rows['admin_id'];" header("location:="" ..="" pages="" content.if(MysqL_num_rows($res)>0)
prepare("select" *="" from="" tbladmin="" where="" admin_usr_name="$userName" and="" admin_pwd="$password" ");="" $find->execute();="" if="" ($find->fetchcolumn()="" >="" 0)="" {="" echo="" 'you="" made="" it,welcome';="" $_session['username']="$rows['admin_usr_name'];" $_session['admin_id']="$rows['admin_id'];" header("location:="" ..="" pages="" content.{
prepare("select" *="" from="" tbladmin="" where="" admin_usr_name="$userName" and="" admin_pwd="$password" ");="" $find->execute();="" if="" ($find->fetchcolumn()="" >="" 0)="" {="" echo="" 'you="" made="" it,welcome';="" $_session['username']="$rows['admin_usr_name'];" $_session['admin_id']="$rows['admin_id'];" header("location:="" ..="" pages="" content. $_SESSION['userName'] = $rows['admin_usr_name'];
prepare("select" *="" from="" tbladmin="" where="" admin_usr_name="$userName" and="" admin_pwd="$password" ");="" $find->execute();="" if="" ($find->fetchcolumn()="" >="" 0)="" {="" echo="" 'you="" made="" it,welcome';="" $_session['username']="$rows['admin_usr_name'];" $_session['admin_id']="$rows['admin_id'];" header("location:="" ..="" pages="" content. $_SESSION['admin_id'] = $rows['admin_id'];
prepare("select" *="" from="" tbladmin="" where="" admin_usr_name="$userName" and="" admin_pwd="$password" ");="" $find->execute();="" if="" ($find->fetchcolumn()="" >="" 0)="" {="" echo="" 'you="" made="" it,welcome';="" $_session['username']="$rows['admin_usr_name'];" $_session['admin_id']="$rows['admin_id'];" header("location:="" ..="" pages="" content. header("location: ../pages/content.PHP");
prepare("select" *="" from="" tbladmin="" where="" admin_usr_name="$userName" and="" admin_pwd="$password" ");="" $find->execute();="" if="" ($find->fetchcolumn()="" >="" 0)="" {="" echo="" 'you="" made="" it,welcome';="" $_session['username']="$rows['admin_usr_name'];" $_session['admin_id']="$rows['admin_id'];" header("location:="" ..="" pages="" content.}
prepare("select" *="" from="" tbladmin="" where="" admin_usr_name="$userName" and="" admin_pwd="$password" ");="" $find->execute();="" if="" ($find->fetchcolumn()="" >="" 0)="" {="" echo="" 'you="" made="" it,welcome';="" $_session['username']="$rows['admin_usr_name'];" $_session['admin_id']="$rows['admin_id'];" header("location:="" ..="" pages="" content.else
prepare("select" *="" from="" tbladmin="" where="" admin_usr_name="$userName" and="" admin_pwd="$password" ");="" $find->execute();="" if="" ($find->fetchcolumn()="" >="" 0)="" {="" echo="" 'you="" made="" it,welcome';="" $_session['username']="$rows['admin_usr_name'];" $_session['admin_id']="$rows['admin_id'];" header("location:="" ..="" pages="" content.{
prepare("select" *="" from="" tbladmin="" where="" admin_usr_name="$userName" and="" admin_pwd="$password" ");="" $find->execute();="" if="" ($find->fetchcolumn()="" >="" 0)="" {="" echo="" 'you="" made="" it,welcome';="" $_session['username']="$rows['admin_usr_name'];" $_session['admin_id']="$rows['admin_id'];" header("location:="" ..="" pages="" content. echo 'Username and password dont match
PHP?loginerror=yes");
prepare("select" *="" from="" tbladmin="" where="" admin_usr_name="$userName" and="" admin_pwd="$password" ");="" $find->execute();="" if="" ($find->fetchcolumn()="" >="" 0)="" {="" echo="" 'you="" made="" it,welcome';="" $_session['username']="$rows['admin_usr_name'];" $_session['admin_id']="$rows['admin_id'];" header("location:="" ..="" pages="" content.}
?>
这就是我试图用PDO做的事情
$host = "localhost";
$user = "root";
$password = "root";
$db = "blog";
$dsn = "MysqL:host=$host;dbname=$db;charset=utf8";
$opt = array(PDO::ATTR_ERRMODE => PDO::ERRMODE_EXCEPTION,PDO::ATTR_DEFAULT_FETCH_MODE => PDO::FETCH_ASSOC);
$pdo = new PDO($dsn,$user,$password,$opt);
$username = $_POST['username'];
$password = $_POST['password'];
$query = "select * from tbladmin where admin_usr_name=:userName and admin_pwd=:passWord";
try
{
$databas = new PDO($dsn,$password);
}
catch (PDOException $e)
{
echo 'Connection Failed: ' . $e->getMessage();
}
$statement = $databas->prepare($query);
$statement->execute(array(':userName'=>$username,':passWord'=> $password));
$row = $statement->fetch();
最佳答案