post mysql更新语句,如何使用update语句更新数据库值?

I am trying to update 'company_name', 'company_add', 'price' as primary key 'id' but it shows me a 'something went wrong' message along with an 'undefined id' error. please help me!

include('data_conn.php');

if(isset($_POST['sub']))

{

$comname=$_POST['cname'];

$comadd=$_POST['cadd'];

$pri=$_POST['price'];

$query ="UPDATE login SET company_name=$comname,company_add=$comadd,price=$pri WHERE id=$id";

$result = mysql_query($query);

echo $result;

if(!$result)

{

echo '

echo 'alert("something went Wrong...:("); location.href="edit.php"';

echo '';

}else{

echo '

echo 'alert("successfully updated!!!"); location.href="edit.php"';

echo '';

}

}

?>

解决方案

Instead of using direct substitution values, you could use below methods to avoid sql injection.

You basically have two options to achieve this:

Using PDO (for any supported database driver):

$stmt = $pdo->prepare('SELECT * FROM employees WHERE name = :name');

$stmt->execute(array('name' => $name));

foreach ($stmt as $row) {

// do something with $row

}

Using MySQLi (for MySQL):

$stmt = $dbConnection->prepare('SELECT * FROM employees WHERE name = ?');

$stmt->bind_param('s', $name);

$stmt->execute();

$result = $stmt->get_result();

while ($row = $result->fetch_assoc()) {

// do something with $row

}

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值