【问题标题】:Problem with identifying index in php html在php html中识别索引的问题
【发布时间】:2020-10-15 09:39:21
【问题描述】:

我的网站必须包含一个带有表格的页面,管理员必须在其中上传一些文件。后来该文件由 php 保存为 mysql 中的 blob,但是,$_FILES 无法找到我的文件输入的索引。请帮忙找出错误。

    <tr>
    <th>ID</th>
    <th>Genre</th>
    <th>Extension</th>
    <th>Description</th>
    <th>Demo-art</th>
    <th>Price</th>
    <th>Upload</th>
    <th>Delete</th>
    </tr>";
    $array=array();
    for($m=0; $row=mysqli_fetch_array($full); $m++)
    {
        $array[$m]=$row['ArtID'];
        echo "<form method='POST' action='checker.php'>";
        echo "<tr>";
        echo "<td><input class='asd' value='$array[$m]' readonly name='name'></td>";
        echo "<td>".$row['Genre']."</td>";
        echo "<td>".$row['Extension']."</td>";
        echo "<td>".$row['Description']."</td>";
        echo "<td><input type='file' name='arts'></td>";
        echo "<td><input class='priceinput' name='price' placeholder='Price'></td>";
        echo "<td><input type='submit' name='Upload' value='Upload'></td>";
        echo "<td><input type='submit' name='Delete' value='Delete'></td>";
        echo "</tr>";
        echo "</form>";
        }
        echo "</table>";
        ;}

PHP 代码

session_start();
$conn= new mysqli("127.0.0.1", "root", "","projectwork") or die ("Can't connect to db");
if($_POST["Upload"]) {
$price=$_POST["price"];
$id=$_POST["name"];
    if ($price!=NULL) {
            if (is_uploaded_file($_FILES['arts']['tmp_name'])) {
                $imgData = addslashes(file_get_contents($_FILES['arts']['tmp_name']));
                $imageProperties = getimageSize($_FILES['arts']['tmp_name']);
                $sql = "Update arts SET imageData='".$imgData."', imageType='".$imageProperties['mime']."' WHERE ArtID=".$id."";
                $current_id = mysqli_query($conn, $sql) or die("<b>Error:</b> Problem on Image Insert<br/>" . mysqli_error($conn));
                    }
        $insert="UPDATE arts SET Price='".$price."', Is_Done='1' WHERE ArtID=".$id."";
        $finalquery=$conn->query($insert);
        echo $price." ".$id;
    }

【问题讨论】:

  • 警告!你对SQL injection攻击敞开大门!您应该使用参数化的prepared statements,而不是像这样直接在查询中使用完全未转义的用户数据。 永远永远永远相信用户输入。
  • 您应该将文件存储在目录中,并将文件引用(名称、路径等)保留在数据库中。
  • 您也不应该向用户/客户端显示来自mysqli_error() 的消息,因为它可能包含敏感数据。记录错误消息并改为显示一般错误消息。

标签: php html sql


【解决方案1】:

除了代码中的安全漏洞之外,表单元素中还缺少enctype='multipart/form-data'。

试试:

echo "<form method='POST' action='checker.php' enctype='multipart/form-data'>";

它会告诉浏览器你正在发送一个文件。

【讨论】:

    猜你喜欢
    • 1970-01-01
    • 1970-01-01
    • 2012-06-05
    • 1970-01-01
    • 2011-11-11
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2011-07-04
    相关资源
    最近更新 更多