̽ÌÖPHP SQL×¢ÈëµÄ½â¾ö˼·
˼·:SQLÀᄀ¿ÉÄܵIJÉÓÃÁ½¸öÒýºÅ±ÕºÏ±äÁ¿;¶Ô±äÁ¿ÖеÄÒýºÅתÒå;¶Ô²»ÄܲÉÓÃ2¸öÒýºÅ±ÕºÏµÄ±äÁ¿,ÏÈÔ¤ÏÈÅжϱäÁ¿ÀàÐÍ;
·½°¸:
1 ËùÓзÇÊýÖµÔËËã(Èç×Ö·û,¼òµ¥ÊýÖµÐ͵ȵÈ)µÄSQL±äÁ¿¶¼¼ÓÒýºÅ;
2 ËùÓзÇÊýÖµÔËËãµÄSQL±äÁ¿µÄÖµ¶¼²ÉÓÃmagic_quotes_gpc»òÕßaddslashesתÒå;
3 ¶ÔÐèÒªÊýÖµÔËËãµÄ±äÁ¿ºÍÆäËû²»ÄܼÓÒýºÅµÄSQL(ÈçINÓï¾ä),Ô¤ÏÈÅжϱäÁ¿ÀàÐÍ.
4 ¹Ø±Õphp.iniµÄdisply_error.(¿ÉÑ¡,Èç²»ÄܹرÕ,Ðè×Ô¼ºÊÖ¶¯ÈÃSQLÓï¾ä²»ÄÜÖ´Ðб¨´í)
php5ժ¼
Ô¤·À´ëÊ©
Ò²ÐíÓÐÈË»á×ÔÎÒ°²Î¿£¬Ëµ¹¥»÷ÕßÒªÖªµÀÊý¾Ý¿â½á¹¹µÄÐÅÏ¢²ÅÄÜʵʩÉÏÃæµÄ¹¥»÷¡£Ã»´í£¬È·ÊµÈç´Ë¡£µ«Ã»ÈËÄܱ£Ö¤¹¥»÷ÕßÒ»¶¨µÃ²»µ½ÕâЩÐÅÏ¢£¬Ò»µ«ËûÃǵõ½ÁË£¬Êý¾Ý¿âÓÐй¶µÄΣÏÕ¡£Èç¹ûÄãÔÚÓÿª·ÅÔ´´úÂëµÄÈí¼þ°üÀ´·ÃÎÊÊý¾Ý¿â£¬±ÈÈçÂÛ̳³ÌÐò£¬¹¥»÷Õ߾ͺÜÈݵõ½µ½Ïà¹ØµÄ´úÂë¡£Èç¹ûÕâЩ´úÂëÉè¼Æ²»Á¼µÄ»°£¬·çÏվ͸ü´óÁË¡£
ÕâЩ¹¥»÷×ÜÊǽ¨Á¢ÔÚ·¢¾ò°²È«Òâʶ²»Ç¿µÄ´úÂëÉϵġ£ËùÒÔ£¬ÓÀÔ¶²»ÒªÐÅÈÎÍâ½çÊäÈëµÄÊý¾Ý£¬ÌرðÊÇÀ´×ÔÓÚ¿Í»§¶ËµÄ£¬°üÀ¨Ñ¡Ôñ¿ò¡¢±íµ¥Òþ²ØÓòºÍ cookie¡£¾ÍÈçÉÏÃæµÄµÚÒ»¸öÀý×ÓÄÇÑù£¬¾ÍËãÊÇÕý³£µÄ²éѯҲÓпÉÄÜÔì³ÉÔÖÄÑ¡£
ÓÀÔ¶²»ÒªÊ¹Ó󬼶Óû§»òËùÓÐÕßÕʺÅÈ¥Á¬½ÓÊý¾Ý¿â¡£ÒªÓÃȨÏÞ±»ÑϸñÏÞÖÆµÄÕʺš£
¼ì²éÊäÈëµÄÊý¾ÝÊÇ·ñ¾ßÓÐËùÆÚÍûµÄÊý¾Ý¸ñʽ¡£PHP Óкܶà¿ÉÒÔÓÃÓÚ¼ì²éÊäÈëµÄº¯Êý£¬´Ó¼òµ¥µÄ±äÁ¿º¯ÊýºÍ×Ö·ûÀàÐͺ¯Êý£¨±ÈÈç is_numeric()£¬ctype_digit()£©µ½¸´Ô Perl ¼æÈÝÕýÔò±í´ïʽº¯Êý¶¼¿ÉÒÔÍê³ÉÕâ¸ö¹¤×÷¡£
Èç¹û³ÌÐòµÈ´ýÊäÈëÒ»¸öÊý×Ö£¬¿ÉÒÔ¿¼ÂÇʹÓà is_numeric() À´¼ì²é£¬»òÕßÖ±½ÓʹÓà settype() À´×ª»»ËüµÄÀàÐÍ£¬Ò²¿ÉÒÔÓà sprintf() °ÑËü¸ñʽ»¯ÎªÊý×Ö¡£
Àý 27-6. Ò»¸öʵÏÖ·ÖÒ³¸ü°²È«µÄ·½·¨
<?php
settype($offset, 'integer');
$query = "SELECT id, name from products ORDER BY name LIMIT 20 OFFSET $offset;";
// Çë×¢Òâ¸ñʽ×Ö·û´®ÖÐµÄ %d£¬Èç¹ûÓà %s ¾ÍºÁÎÞÒâÒåÁË
$query = sprintf("SELECT id, name from products ORDER BY name LIMIT 20 OFFSET %d;",
$offset);
?>
ʹÓÃÊý¾Ý¿âÌØ¶¨µÄÃô¸Ð×Ö·ûתÒ庯Êý£¨±ÈÈç mysql_escape_string() ºÍ sql_escape_string()£©°ÑÓû§Ìá½»ÉÏÀ´µÄ·ÇÊý×ÖÊý¾Ý½øÐÐתÒå¡£Èç¹ûÊý¾Ý¿âûÓÐרÃŵÄÃô¸Ð×Ö·ûתÒ
Ïà¹ØÎĵµ£º
##################################################
# ÉùÃ÷£º
# ±¾ÎÄת×ÔCSDN£¬Óû§ID£ºhtl258
# ÔÌûµØÖ·£ºhttp://blog.csdn.net/htl258/archive/2010/05/13/5588454.aspx
####### ......
ǰ¶Îʱ¼äѧµÄÓйØsqlµÄÏà¹ØÖªÊ¶,ºÜ¶à¶¼Ã»¼°Ê±È¥ÕûÀí,½ñÌì¸ÕºÃÓÐʱ¼äÓÐûÐÄÇé×öÆäËûµÄÊÇ,¾ÍÕûÀíÕûÀí°É
Ò»Ö±ÒÔΪ×ö¿ª·¢µÄ¶ÔÊý¾Ý¿â²Ù×÷·½ÃæµÄÒªÇó²»»áºÜ¸ß,Ö»Òª»á¶ÔÊý¾ÝÔöɾ¸Ä²é¾ÍokÁË.ÏÖÔÚ²ÅÖªµÀ¶ÔÊý¾Ý¿âµÄ²Ù×÷»¹Ó¦¸Ã°üÀ¨Ð´´æ´¢ºÍº¯Êý,»¹Òª´´½¨ÐòÁС¢Ë÷Òý,ÊÓͼµÈ.
......
¾²âÊÔ Ã»ÓÐÎÊÌâ
<?
class smtp
{
/* Public Variables */
var $smtp_port;
var $time_out;
var $host_name;
var $log_file;
var $relay_host;
var $debug;
var $auth;
var $user;
var $pass;
/* Private Variables */
var $sock;
/* Constractor */
function smtp($relay_host = " ......
Á¬½Ó²éѯ
¡¡¡¡Í¨¹ýÁ¬½ÓÔËËã·û¿ÉÒÔʵÏÖ¶à¸ö±í²éѯ¡£Á¬½ÓÊǹØÏµÊý¾Ý¿âÄ£Ð͵ÄÖ÷ÒªÌØµã£¬Ò²ÊÇËüÇø±ðÓÚÆäËüÀàÐÍÊý¾Ý¿â¹ÜÀíϵͳµÄÒ»¸ö±êÖ¾¡£
¡¡¡¡ÔÚ¹ØÏµÊý¾Ý¿â¹ÜÀíϵͳÖУ¬±í½¨Á¢Ê±¸÷Êý¾ÝÖ®¼äµÄ¹ØÏµ²»±ØÈ·¶¨£¬³£°ÑÒ»¸öʵÌåµÄËùÓÐÐÅÏ¢´æ·ÅÔÚÒ»¸ö±íÖС£µ±¼ìË÷Êý¾Ýʱ£¬Í¨¹ýÁ¬½Ó²Ù×÷²éѯ³ö´æ·ÅÔÚ¶à¸ö±íÖеIJ»Í¬ÊµÌåµÄ ......
Áª½ÓÌõ¼þ¿ÉÔÚ from »ò WHERE ×Ó¾äÖÐÖ¸¶¨£¬½¨ÒéÔÚ from ×Ó¾äÖÐÖ¸¶¨Áª½ÓÌõ¼þ¡£WHERE ºÍ HAVING ×Ó¾äÒ²¿ÉÒÔ°üº¬ËÑË÷Ìõ¼þ£¬ÒÔ½øÒ»²½É¸Ñ¡Áª½ÓÌõ¼þËùÑ¡µÄÐС£
Áª½Ó¿É·ÖΪÒÔϼ¸Àࣺ
1. ......