Re: access data in php

Поиск
Список
Период
Сортировка
Искать
От
Scott Marlowe
Тема
Re: access data in php
Дата
Msg-id
dcc563d10901021214i77f91688i484ed3bfeb355dd8@mail.gmail.com
Ответ на
Список
Дерево обсуждения
access data in php Marc Fromm <Marc.Fromm@wwu.edu>
Re: access data in php ioguix@free.fr
Re: access data in php Marc Fromm <Marc.Fromm@wwu.edu>
Re: access data in php "Scott Marlowe" <scott.marlowe@gmail.com>
Re: access data in php Marc Fromm <Marc.Fromm@wwu.edu>
Re: access data in php Chander Ganesan <chander@otg-nc.com>
Re: access data in php "Scott Marlowe" <scott.marlowe@gmail.com>
Re: access data in php "Scott Marlowe" <scott.marlowe@gmail.com>
On Fri, Jan 2, 2009 at 12:40 PM, Marc Fromm  wrote:
> This is my code:
>  $dbconn = pg_connect("host=localhost port=5432 user=postgres dbname=studentalerts");
>
> if(isset($_GET["value"])){
>        $w_number=$_GET["value"];
> }

You need to scrub user input.  use pg_escape_string($_GET['value'])

> //echo $w_number;
>
> $query = "select first_name, last_name, alert from alert_list where w_number='$w_number'";
> $result = pg_query($dbconn,$query);
> if (!$result) {
>    echo "Problem with query " . $query . "
"; > echo pg_last_error(); > exit(); > } > > $rows = pg_fetch_assoc($result); Change this to $rows = pg_num_rows($result); > if ($rows==0){ > echo "There are no alerts for $w_number!\n\n"; > }else{ > $result = pg_query($dbconn,$query); > $count=1; > while ($row = pg_fetch_array($result)){ > echo "Alert $count: "; > echo htmlspecialchars($row['first_name']) . " "; > echo htmlspecialchars($row['last_name']); > echo "\n"; > echo htmlspecialchars($row['alert']); > echo "\n\n"; > $count++; > } > } > if ($w_number==""){echo "Enter a W number!\n\n";} > echo "End of line"; > > pg_free_result($result); > pg_close($dbconn); > ?> > > -----Original Message----- > From: Scott Marlowe [mailto:scott.marlowe@gmail.com] > Sent: Friday, January 02, 2009 10:28 AM > To: ioguix@free.fr > Cc: Marc Fromm; pgsql-admin@postgresql.org > Subject: Re: [ADMIN] access data in php > > On Fri, Jan 2, 2009 at 11:09 AM, wrote: >> pg_fetch_assoc behave like pg_fetch_array: it increments the internal >> pointer to the current result. >> So if you call it once, then pg_fetch_array will return the 2nd result >> in the result set. > > Wow, I'm so used to seeing > > $rows = pg_num_rows() that that's what I saw up there. > -- When fascism comes to America, it will be draped in a flag and carrying a cross - Sinclair Lewis
В списке pgsql-admin по дате отправления
От: Chander Ganesan
Дата:
Сообщение: Re: access data in php
От: Jumping
Дата:
Сообщение: data convert
FAQ