cURL和PHP显示“1”

时间:2012-06-06 06:12:07

标签: php mysql database curl

我有一个PHP脚本,我想从数据库读取服务器并使用cURL连接到它们。服务器响应sql查询的结果。问题是每个服务器响应后的脚本显示数字1.输出如下:

  

服务器1:一些结果

     

1Server 2:一些结果

     

1Server 3:一些结果

     

1

以下是从数据库读取服务器并连接到它们的代码:

<?php

$mysql_id = mysql_connect('localhost', 'ms', 'pass');
mysql_select_db('servers', $mysql_id);
mysql_query("SET NAMES utf8");

$query = "SELECT * FROM svr";
$result = mysql_query($query);
$num = mysql_num_rows($result);
while ($data = mysql_fetch_assoc($result))
{
    $server[] = $data;
}

mysql_close($mysql_id);

$i = 0;
while($i < $num) {
    $dealer = $server[$i]['dealer'];

    echo $dealer . "<br />";

    $data = "val=a"; //just for testing                                                                    

    $ch = curl_init();
    curl_setopt($ch, CURLOPT_URL, $url);
    curl_setopt($ch, CURLOPT_CUSTOMREQUEST, "POST");                                                                     
    curl_setopt($ch, CURLOPT_POSTFIELDS, $data);    
    curl_setopt($ch, CURLOPT_HTTPHEADER, array(                                                                                                                                                       
        'Content-Type: text/html; charset=utf-8')                                                                       
    );                                                                                                                                                                                   

    $result = curl_exec($ch);
    echo $result;
    $i++;
}

?>

我发现1显示为“echo $ result;”并且创建响应的代码是:

<?php

$mysql_id1 = mysql_connect('localhost', 'ms', 'pass');
mysql_select_db('servers', $mysql_id1);
mysql_query("SET NAMES utf8");

    $query2 = "SELECT * FROM data";
    $result2 = mysql_query($query2);
    $num2 = mysql_num_rows($result2);
    while ($data2 = mysql_fetch_assoc($result2))
    {
        $deli[] = $data2;
    }
    $i1 = 0;
    $space = "&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;";
    while ($i1 < $num2) {
        echo $space . $deli[$i1]['id'] . " ";
        echo $deli[$i1]['artikel'] . " ";
        echo $deli[$i1]['znamka'] . " ";
        echo $deli[$i1]['model'] . " ";
        echo $deli[$i1]['letnik'] . " ";
        echo $deli[$i1]['cena'] . " € ";
        echo $deli[$i1]['zaloga'] . "<br />";
        $i1++;
    }
    echo "<br />";
    mysql_close($mysql_id1);
?>

请帮帮我

4 个答案:

答案 0 :(得分:55)

使用CURLOPT_RETURNTRANSFER选项。否则,cURL将自动回显数据并返回true(通过echo转换为1。)

curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);

答案 1 :(得分:9)

您需要使用CURLOPT_RETURNTRANSFEcurl_exec返回状态代码并将响应发送到stdout:

curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);

答案 2 :(得分:0)

伙计,如果用户可以更改经销商字段或$ deli字段,则您已在此处存储了XSS漏洞。


 $dealer = $server[$i]['dealer'];
 echo $dealer . "<br />";
 echo $space . $deli[$i1]['id'] . " ";
 ...etc

使用


 $dealer = $server[$i]['dealer'];
 echo $dealer . "<br />";
 echo $space . $deli[$i1]['id'] . " ";
 ...etc
解决这个问题

答案 3 :(得分:-1)

使用CURLOPT_RETURNTRANSFE或者它会返回状态代码并将回复发送到stdout

curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);