【问题标题】:php Code working offline but not onlinephp代码离线工作但不在线
【发布时间】:2013-10-18 08:30:54
【问题描述】:

我在调用使用 sql 查询 MySQL 数据库的 php 脚本时遇到问题。代码离线工作,但是当我上传到服务器时,代码循环了 5 次并返回一个奇怪的 json 字符串。我检查了 phpMyAdmin 中的 sql,它返回了正确的值。

我正在使用以下 javascript 调用脚本:

            var jsonData1 = $.ajax({
                url: "php/ResidualArisingsdata.php?PrimaryKey=<?php echo $primarykey ?>",
                dataType: "json",
                async: false
            }).responseText;

并且 php 脚本是(删除了登录详细信息)

<?php 
    $_SESSION['url'] = $_SERVER['REQUEST_URI'];
    $primarykey = $_GET['PrimaryKey'];    

// These variables define the connection information for your MySQL database 
    $username = "xxx"; 
    $password = "xxx"; 
    $host = "localhost"; 
    $dbname = "xxx"; 

    $mysqli = new mysqli($host, $username, $password, $dbname);

    if (mysqli_connect_errno()) {
        printf("Connect failed: %s\n", mysqli_connect_error());
    exit();
    }

    $SQLString = "SELECT PrimaryKey,
        Name,
        `HouseholdRecyclingRate2005/06`,
        `HouseholdRecyclingRate2006/07`,
        `HouseholdRecyclingRate2007/08`,
        `HouseholdRecyclingRate2008/09`,
        `HouseholdRecyclingRate2009/10`,
        `HouseholdRecyclingRate2010/11`,
        `HouseholdRecyclingRate2011/12`
        FROM `districts_recyclingrates`
        WHERE `districts_recyclingrates`.PrimaryKey =" . $primarykey;       

    $result = $mysqli->query($SQLString); 

    $rows = array();
    $table = array();
    $table['cols'] = array(
        array('label' => 'Year', 'type' => 'string'),
        array('label' => 'Name', 'type' => 'number'),
        array('label' => 'UK Average', 'type' => 'number')
    );

    foreach($result as $r) {
    $temp = array();


    $temp[] = array('v' => "05/06"); 
    $temp[] = array('v' =>(int) $r['`HouseholdRecyclingRate2005/06`']);
    $temp[] = array('v' => "25.2"); 
    $rows[] = array('c' => $temp);
    unset($temp);
    $temp[] = array('v' => "06/07"); 
    $temp[] = array('v' =>(int) $r['HouseholdRecyclingRate2006/07']);
    $temp[] = array('v' => "29.7");
    $rows[] = array('c' => $temp);
    unset($temp);
    $temp[] = array('v' => "07/08"); 
    $temp[] = array('v' =>(int) $r['HouseholdRecyclingRate2007/08']);
    $temp[] = array('v' => "33.6");
    $rows[] = array('c' => $temp);
    unset($temp);
    $temp[] = array('v' => "08/09"); 
    $temp[] = array('v' =>(int) $r['HouseholdRecyclingRate2008/09']);
    $temp[] = array('v' => "36.4");
    $rows[] = array('c' => $temp);
    unset($temp);
    $temp[] = array('v' => "09/10"); 
    $temp[] = array('v' =>(int) $r['HouseholdRecyclingRate2009/10']);
    $temp[] = array('v' => "38.2");
    $rows[] = array('c' => $temp);
    unset($temp);
    $temp[] = array('v' => "10/11"); 
    $temp[] = array('v' =>(int) $r['HouseholdRecyclingRate2010/11']);
    $temp[] = array('v' => "40.3");
    $rows[] = array('c' => $temp);
    unset($temp);
    $temp[] = array('v' => "11/12"); 
    $temp[] = array('v' =>(int) $r['HouseholdRecyclingRate2011/12']);
    $temp[] = array('v' => "42.1");
    $rows[] = array('c' => $temp);
    }

    $table['rows'] = $rows;
    // convert data into JSON format
    $jsonTable = json_encode($table);
    echo $jsonTable;

    mysqli_close($mysqli);
?>

返回的 json(用 console.log 标识)如下所示,其中数据库值为 0,foreach 已循环 5 次。

{"cols":[{"label":"Year","type":"string"},{"label":"Name","type":"number"},{"label":"UK Average","type":"number"}],"rows":[{"c":[{"v":"05\/06"},{"v":0},{"v":"25.2"}]},{"c":[{"v":"06\/07"},{"v":0},{"v":"29.7"}]},{"c":[{"v":"07\/08"},{"v":0},{"v":"33.6"}]},{"c":[{"v":"08\/09"},{"v":0},{"v":"36.4"}]},{"c":[{"v":"09\/10"},{"v":0},{"v":"38.2"}]},{"c":[{"v":"10\/11"},{"v":0},{"v":"40.3"}]},{"c":[{"v":"11\/12"},{"v":0},{"v":"42.1"}]},{"c":[{"v":"05\/06"},{"v":0},{"v":"25.2"}]},{"c":[{"v":"06\/07"},{"v":0},{"v":"29.7"}]},{"c":[{"v":"07\/08"},{"v":0},{"v":"33.6"}]},{"c":[{"v":"08\/09"},{"v":0},{"v":"36.4"}]},{"c":[{"v":"09\/10"},{"v":0},{"v":"38.2"}]},{"c":[{"v":"10\/11"},{"v":0},{"v":"40.3"}]},{"c":[{"v":"11\/12"},{"v":0},{"v":"42.1"}]},{"c":[{"v":"05\/06"},{"v":0},{"v":"25.2"}]},{"c":[{"v":"06\/07"},{"v":0},{"v":"29.7"}]},{"c":[{"v":"07\/08"},{"v":0},{"v":"33.6"}]},{"c":[{"v":"08\/09"},{"v":0},{"v":"36.4"}]},{"c":[{"v":"09\/10"},{"v":0},{"v":"38.2"}]},{"c":[{"v":"10\/11"},{"v":0},{"v":"40.3"}]},{"c":[{"v":"11\/12"},{"v":0},{"v":"42.1"}]},{"c":[{"v":"05\/06"},{"v":0},{"v":"25.2"}]},{"c":[{"v":"06\/07"},{"v":0},{"v":"29.7"}]},{"c":[{"v":"07\/08"},{"v":0},{"v":"33.6"}]},{"c":[{"v":"08\/09"},{"v":0},{"v":"36.4"}]},{"c":[{"v":"09\/10"},{"v":0},{"v":"38.2"}]},{"c":[{"v":"10\/11"},{"v":0},{"v":"40.3"}]},{"c":[{"v":"11\/12"},{"v":0},{"v":"42.1"}]},{"c":[{"v":"05\/06"},{"v":0},{"v":"25.2"}]},{"c":[{"v":"06\/07"},{"v":0},{"v":"29.7"}]},{"c":[{"v":"07\/08"},{"v":0},{"v":"33.6"}]},{"c":[{"v":"08\/09"},{"v":0},{"v":"36.4"}]},{"c":[{"v":"09\/10"},{"v":0},{"v":"38.2"}]},{"c":[{"v":"10\/11"},{"v":0},{"v":"40.3"}]},{"c":[{"v":"11\/12"},{"v":0},{"v":"42.1"}]}]} 

不胜感激。提前致谢。

【问题讨论】:

  • $temp = array(); 应该在您的 foreach() 循环之外。
  • @Ben - 当它在循环内也被取消设置时(但没有重新创建!)。这个问题问题太多了,代码和数据库都不知道从何说起!
  • @user24....:您可能希望首先将代码发布到 codereview.stackexchange.com 并阅读 catb.org/esr/faqs/smart-questions.html
  • 嗨,本,谢谢。我已经尝试过,但它对 json 输出没有任何影响。
  • 请,在您编写任何更多的 SQL 接口代码之前,您必须阅读 proper SQL escaping 以避免严重的 SQL injection bugs。当使用mysqli 时,您应该使用参数化查询和bind_param 将用户数据添加到您的查询中。 从不使用字符串插值来完成此操作。 $primarykey 直接从 $_GET 中提取并注入到您的查询中,这会造成严重问题。

标签: javascript php mysql json google-visualization


【解决方案1】:

您可以使用json_last_error 函数在 php 中调试 JSON 错误。

一个例子是:

<?php
// An invalid UTF8 sequence
$text = "\xB1\x31";

$json  = json_encode($text);
$error = json_last_error();

var_dump($json, $error === JSON_ERROR_UTF8);
?>

无论如何,您的代码中存在信息安全漏洞,称为 XSS(跨站点脚本)。

位于您的 javascript 代码中,这一行:

url: "php/ResidualArisingsdata.php?PrimaryKey=",

您正在打印来自用户的未经验证的输入,请在以下位置阅读:

http://en.wikipedia.org/wiki/Cross-site_scripting

第二个缺陷是 SQL 注入,您将来自用户的未经验证的输入包含到您的 SQL 查询中,这是非常危险的事情,请在此处阅读: http://en.wikipedia.org/wiki/SQL_injection

【讨论】:

  • 感谢您的建议。你能告诉我为什么代码循环了五次吗?排序后我会整理出安全错误。
猜你喜欢
  • 1970-01-01
  • 2012-01-14
  • 1970-01-01
  • 1970-01-01
  • 2015-06-12
  • 2015-07-16
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
相关资源
最近更新 更多