【问题标题】:Passing PHP variables into MySQL将 PHP 变量传递到 MySQL
【发布时间】:2017-05-10 21:28:35
【问题描述】:

我在 PHP 中有一个将值插入 MYSQL 表的函数。

function insertRow($db, $new_table, $ID, $Partner, $Merchant)
{
    $insert = "INSERT INTO " .$new_table. " VALUES(number, "string", "string")"
    $q = mysqli_query($db, $insert);
}

我正在努力自定义 VALUES 部分。我需要数字、字符串和字符串分别是 PHP 中的 ID、Partner 和 Merchant 变量。

我试过了

function insertRow($db, $new_table, $ID, $Partner, $Merchant)
{
    $insert = "INSERT INTO " .$new_table. " VALUES(" .$ID . $Partner . $Merchant . ")";
    $q = mysqli_query($db, $insert);
}

也是。但它似乎不起作用,因为对于 SQL,字符串值必须用引号括起来。但是,如果我更改代码,使其 ."$ID" 。 “$伙伴”。 “$商人”。 ")";因此变量根据需要放在引号中,它们不再是 PHP 变量。如何让我的 PHP 变量包含在引号中,以便正确执行 SQL?

【问题讨论】:

  • 阅读数据库转义。

标签: php mysql variables


【解决方案1】:

使用连接的其他答案是简单的。最好的方法是使用准备好的语句,这将使您的代码更加安全。

$insert = "INSERT INTO " .$new_table. " VALUES(?, ?, ?)";
$q = mysqli_prepare($db, $insert);
mysqli_stmt_bind_param($q, "iss", $ID, $Partner, $Merchant);
mysqli_stmt_execute($q);

进行参数化查询意味着您的查询和数据是分开发送的。这意味着查询的结构已经存在,因此不能被插入数据中的任何其他内容更改,这意味着您可以安全地避免 SQL 注入。

参见 PHP 手册:

【讨论】:

  • 这是正确的方法。如果没有这些参数,您就会面临攻击。
【解决方案2】:

嗯,有很多方法可以做到这一点:

字符串连接

注意数据库除外的数据类型。在您的问题中,您错过了分隔值的逗号:

$insert = 'INSERT INTO ' . $new_table . ' VALUES(' . $ID . ', \'' . $Partner . '\', \'' . $Merchant '\')';

有很多方法可以修改字符串连接示例。考虑有关单引号和双引号的 php 文档。在您的示例中,您在单引号的含义中使用了双引号。使用双引号,您可以将变量直接放入其中。所以我把它改成了单引号。

sprintf

$insert = sprintf('INSERT INTO %s VALUES(%s, \'%s\', \'%s\');', $new_table, $ID, $Partner, $Merchant);

有关此便捷功能的更多信息,请参阅文档:http://www.php.net/sprintf

准备好的陈述

因为SQL Injection,我宁愿建议你使用这种方法。在上面的示例中,您需要注意字符串转义。可以使用mysql_real_escape。但它可能不适用于所有场景。

因此,准备好的语句要好得多:

$insert = 'INSERT INTO ' .$new_table. ' VALUES(?, ?, ?)';
$q = mysqli_prepare($db, $insert);
mysqli_stmt_bind_param($q, "iss", $ID, $Partner, $Merchant);
mysqli_stmt_execute($q);

PS:使用面向对象的方式对准备好的语句也更好,因为你有更多的机会这样做。请参阅MySQLi 类样式和PDO 的文档。

【讨论】:

    【解决方案3】:

    串联

    $insert = "INSERT INTO " .$new_table. " VALUES(".$ID.", '".$Partner."', "."'"$Merchant"')";
    

    【讨论】:

      【解决方案4】:

      试试这个:

      function insertRow($db, $new_table, $ID, $Partner, $Merchant)
      {
          $insert = "INSERT INTO " .$new_table. " VALUES( '" .$ID."','" . $Partner."','". $Merchant . "')";
          $q = mysqli_query($db, $insert);
      }
      

      或者你可以使用

      function insertRow($db, $new_table, $ID, $Partner, $Merchant)
      {
          $insert = "INSERT INTO " .$new_table. " VALUES( '$ID','$Partner','$Merchant')";
          $q = mysqli_query($db, $insert);
      }
      

      【讨论】:

        【解决方案5】:

        嗯...它是一个查询与它只是一个与其他字符串一样的事实没有区别。您完全有能力添加 $new_table 值,那么是什么阻止您执行其他操作?

        $insert = "INSERT INTO ".$new_table." VALUES (".$ID.", '".$Partner."', '".$Merchant.")";
        

        这假设您已经采取了必要的步骤来清理这些值。

        【讨论】:

          【解决方案6】:

          试试这个:

          $insert = "INSERT INTO $new_table VALUES(number, '{$string}', '{$string}')";
          

          【讨论】:

            【解决方案7】:
            $insert = "INSERT INTO $new_table VALUES($ID,'$Partner','$Merchant')";
            

            【讨论】:

              猜你喜欢
              • 2018-06-02
              • 1970-01-01
              • 1970-01-01
              • 2015-08-24
              • 2018-10-22
              • 2012-10-07
              • 1970-01-01
              • 1970-01-01
              • 1970-01-01
              相关资源
              最近更新 更多