如何使用动态表名防止SQL注入?
PDO 在这里没用。以及MySQL_REAL_EXECH_String。质量极差。
mysql_real_escape_string
<script type="text/javascript"> var layer; window.location.href = "example3.php?layer="+ layer; <?php //Make a MySQL connection $query = "SELECT Category, COUNT(BUSNAME) FROM ".$_GET['layer']." GROUP BY Category"; $result = mysql_query($query) or die(mysql_error());
$layer = mysql_real_escape_string($_GET['layer']);$query = "SELECT Category, COUNT(BUSNAME) FROM `".$layer."` GROUP BY Category";
噜噜哒
慕标5832272