gpt4 book ai didi

javascript - 尝试 POST "select"HTML 表单输入时出现 PHP 错误

转载 作者:行者123 更新时间:2023-11-29 23:10:08 24 4
gpt4 key购买 nike

因此,我创建了一个非常简单的 HTML 调查表单,其中只有一个选择下拉输入和一个文本输入字段。仅当选择字段位于“其他”选项上时,文本输入才会显示。所以这一切都很好,我有 JavaScript 处理所有这一切,而且效果很好。

现在,当我尝试将表单值 POST 到 PHP 文件,然后将这些值插入到我的数据库表中时,问题就出现了。每次尝试提交表单时,我都会收到此错误:

Error: INSERT INTO survey (select, other) VALUES ('flyer','')
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ' other) VALUES ('flyer','')' at line 1

由于奇怪的单引号似乎切断了 sql 字符串的第一部分,我相信我以某种方式将 SQL 注入(inject)到我的表单 POST 或 PHP 验证中。我已经多次检查代码来寻找奇怪的引号,从头开始完全重写了表单,从数据库中检查了表和行名称,甚至抓取了一个我知道在其他地方有效的 SQL 字符串,将其更改为有效这里。不幸的是,我总是遇到同样的错误,所以我非常感谢你们能借给我任何见解或帮助。

我的 HTML 表单:

  <form action="includes/survey.php" method="POST" id="hear_form">
<label for="hear_select">How did you here about us?</label>
<br>

<select id="hear_select" name="hear_select">
<option value='flyer'>
Flyer left on door
</option>
<option value='email'>
Email from Troop
</option>
<option value='sodo'>
SODO News
</option>
<option value='conway'>
Conway News
</option>
<option value='southwest'>
Southwest Orlando Bulletin
</option>
<option value='winter'>
Winter Park Observer
</option>
<option value='baldwin'>
Baldwin Park Living
</option>
<option value='facebook'>
Facebook
</option>
<option value='neighborhood'>
Neighborhood posting
</option>
<option value='other'>
Other
</option>
</select>

<label id="otherlabel" for="other_type">Where else did you hear about us?</label>
<input id="other_type" type="text" name="other_type" maxlength="200" value="">

<input type="submit" value="Submit" id="hear_submit">
</form>

我的 PHP:

require_once 'db_con.php';
require_once 'functions.php';

$selectErr = "";
$otherErr = "";

//validating inputs
if ($_SERVER["REQUEST_METHOD"] == "POST"){
if (empty($_POST["hear_select"])){
$selectErr = "* An answer is required";
$valid = false;
}else{
$select = test_input($_POST["hear_select"]);
$valid = true;
}

if (empty($_POST["other_type"])) {
$other = test_input($_POST["other_type"]);
$valid = true;
}else{
if((strlen($_POST["other_type"]) < 200)){
$other = test_input($_POST["other_type"]);
$valid = true;
}else{
$otherErr = "* An answer must have less than 200 characters";
$valid = false;
}
}


if($selectErr != '' || $otherErr != ''){
$valid = false;
}

if($valid){
var_dump($_POST);
//inserting variables into the database
$sql = "INSERT INTO survey (select, other) VALUES ('$select','$other')";
//checking if all worked, if it did redirect page top next step
if ($mysqli->query($sql) === TRUE) {
header( 'Location: index.php' ) ;
} else {
echo "Error: " . $sql . "<br>" . $mysqli->error;
}

$mysqli->close();

exit;
}
}

function test_input($data) {
$data = trim($data);
$data = str_replace('"', "", $data);
$data = str_replace("'", "", $data);
$data = stripslashes($data);
$data = htmlspecialchars($data);
return $data;
}

最佳答案

该查询的问题在于“select”是 SQL 标准中的保留关键字,如果要将其用作列名,则必须对其进行正确转义。

最好的选择是重命名该列,或者在查询中对其进行转义。请参阅以下链接了解更多详细信息。

Escaping reserved keywords

关于javascript - 尝试 POST "select"HTML 表单输入时出现 PHP 错误,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/28122120/

24 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com