if(isset($_GET['action'])&&$_GET['action']=='ser'){$tmp=!empty($_POST)?$_POST:$_GET;$whr=array();if(!empty($tmp['bookname'])){$whr[]="booknameLIKE'%{$tmp['bookname']}%'";...
if(isset($_GET['action'] ) && $_GET['action']=='ser'){
$tmp= !empty($_POST) ? $_POST : $_GET;
$whr = array();
if(!empty($tmp['bookname'])){
$whr[]= " bookname LIKE '%{$tmp['bookname']}%'";
$args .="&bookname={$tmp['bookname']}";
}else{
$tmp['bookname'] = "";
}
if(!empty($tmp['author'])){
$whr[]= "author LIKE '%{$tmp['author']}%'";
$args .="&author={$tmp['author']}";
}else{
$tmp['author'] = "";
}
if(!empty($tmp['minprice'])){
$whr[]= "price >= '{$tmp['minprice']}'";
$args .="&minprice={$tmp['minprice']}";
}else{
$tmp['minprice'] = "";
}
if(!empty($tmp['maxprice'])){
$whr[]= "price <= '{$tmp['maxprice']}'";
$args .="&maxprice={$tmp['maxprice']}";
}else{
$tmp['maxprice'] = "";
}print_r($whr)."
";
if(!empty($whr)){
$where = "where ".implode(" and ",$whr);
}else{
$where = "";
}
}
try{
$ser= $pdo-> prepare ( "SELECT count(*) as total FROM `books` :where");
$ser-> bindParam("where",$where);
$ser-> execute();
}catch(PDOException $error){
echo "错误:".$error -> getMessage()."
";
}
print_r($ser);
$sere = $ser-> fetch(PDO::FETCH_ASSOC);
$page = new Page($sere['total'],$num,$args);
SQLSTATE[42000]: Syntax error or access violation: 1064 You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '''' at line 1
请问是什么问题导致的
展开