10. 亳仄亠 - 舒舒从舒
弌从p亳仗 亰a 于xo亟 于 c亳ce仄aa 亳仄a c亳仆a从c亳c o po亟a:
$sql = "SELECT * FROM users WHERE username =
'$user' AND password = '$pass'".
A从o 从仄 a亰亳 亰a磦从a 仆apy亳e仍 仗o亟a亟e e亟亳仆亳仆a
从舒于亳从舒 亰a 仗ope弍亳e仍c从o 亳仄e 亳 仗po亳亰于o仍仆a
仗apo仍a, 亰a磦从aa e 于p仆e c仍e亟仆aa 亞pe从a:
You have an error in your SQL syntax; check the
manual that corresponds to your MySQL server
version for the right syntax to use near 'WHERE
username = ' ' ' AND password = 'sometext
11. 舒亳舒
SQL 亳仆亢e从亳pa仆eo 仄仂亢亠 亟舒 弍亟亠
亳亰弍亠亞仆舒仂. c亳从亳 仗po仄e仆仍亳于亳, 从o亳o ce
于从ap于a 于 e亟仆a MySQL 亰a磦从a, p磡于a 亟a
弍亟a 亳仍p亳pa仆亳 c y仆从亳a
mysql_real_escape_string(). B 亞op仆亳
仗p亳仄ep, o于a ca 仗po仄e仆仍亳于亳e $user 亳
$pass. C亳仆a从c亳c e 从舒从仂 c仍e亟于a: $user =
mysql_real_escape_string($user) 亳 a从a 亰a
$pass.