PHP:对下拉菜单句柄注入进行选择查询

时间:2018-09-09 03:29:40

标签: php mysql phpmyadmin sql-injection

如何改进此代码以使其处理带有引号的注入和输入?

$result = $conn->query("select bookName from Book");

echo "<select name='bookName'>";

while ($row = $result->fetch_assoc()) {
  unset($bookName);
  $bookName = $row['bookName'];
  echo '<option value="'.$bookName.'">'.$bookName.'</option>';
}

0 个答案:

没有答案