3

我正在努力做到这一点,如果他们的 IP 在数据库中,那么他们就无法发送电子邮件。在 php54_errors 文件中它说

[30-Dec-2012 18:25:26 Europe/Dublin] PHP Warning:  mysql_num_rows() expects parameter 1 to be resource, string given in C:\inetpub\wwwroot\Submit.php on line 6
[30-Dec-2012 18:25:26 Europe/Dublin] PHP Warning:  mysql_num_rows() expects parameter 1 to be resource, null given in C:\inetpub\wwwroot\Submit.php on line 7

我的 PHP 代码是这样的

<?php
include("connect.php");
mysql_select_db("ip", $con);
$ip = mysql_real_escape_string($_SERVER['REMOTE_ADDR']);
$query = "SELECT * FROM ip WHERE ip='$ip'";
$result = mysql_num_rows($query);
if (mysql_num_rows($result) > 0) {
    echo "You have already registered!";
}
else { 
    echo"Your request has been sent!";
    $to = "admin@prisoneternity.org.uk";
    $subject = "Guard Application";
    $from = "guardapplication@prisoneternity.org.uk";
    $headers = "From:" . $from;
    $message = "IGN = " . $_POST["Username"] . "</br>\n\nage = " . $_POST["age"] . "</br>\n\nreason = " . $_POST["reason"] . "</br>\n\nHow many times have they been guard = " . $_POST["guard"] . "</br>\n\nOther Details = " . $_POST["text"];
    mail($to,$subject,$message,$headers);
    header ("Location: index.php?email=yes");
    session_start();
    mysql_query("INSERT INTO ip (IP) VALUES ('$ip')");
}
?>
4

2 回答 2

2
$result = mysql_num_rows($query);
if (mysql_num_rows($result) > 0) {

应该:

$result = mysql_query($query);
if (mysql_num_rows($result) > 0) {

您没有运行mysql_query(),而是调用mysql_num_rows()了两次。简单事故=o)顺便说一句,您应该使用PDOMySQLi

还:

echo"Your request has been sent!";
$to = "admin@prisoneternity.org.uk";
$subject = "Guard Application";
$from = "guardapplication@prisoneternity.org.uk";
$headers = "From:" . $from;
$message = "IGN = " . $_POST["Username"] . "</br>\n\nage = " . $_POST["age"] . "</br>\n\nreason = " . $_POST["reason"] . "</br>\n\nHow many times have they been guard = " . $_POST["guard"] . "</br>\n\nOther Details = " . $_POST["text"];
mail($to,$subject,$message,$headers);
header ("Location: index.php?email=yes");
session_start();
mysql_query("INSERT INTO ip (IP) VALUES ('$ip')");

应该:

$to = "admin@prisoneternity.org.uk";
$subject = "Guard Application";
$from = "guardapplication@prisoneternity.org.uk";
$headers = "From:" . $from;
$message = "IGN = " . $_POST["Username"] . "</br>\n\nage = " . $_POST["age"] . "</br>\n\nreason = " . $_POST["reason"] . "</br>\n\nHow many times have they been guard = " . $_POST["guard"] . "</br>\n\nOther Details = " . $_POST["text"];
mail($to,$subject,$message,$headers);
//header ("Location: index.php?email=yes");
session_start();
echo"Your request has been sent!";
mysql_query("INSERT INTO ip (IP) VALUES ('$ip')");

您不能在header()或之前回显内容session_start(),在您进行重定向时也不会看到回显的文本。你需要选择你想做什么。我评论了header()上面的内容,但你可以做相反的事情。还要确保清理所有$_POST\r\n字符,以防止邮件头注入攻击

于 2012-12-30T18:37:37.747 回答
1

在第二行,mysql_num_rows返回一个整数,因为$result变量已经在调用函数,如果这有意义的话。将其更改为:

$result = mysql_num_rows($query);
if ($result > 0) {

此外,您没有运行查询:

$query = "SELECT * FROM ip WHERE ip='$ip'";

将上面的行更改为:

$query = mysql_query("SELECT * FROM ip WHERE ip='$ip'");


在旁注中,mysql_*函数已被弃用。我会切换到PDOor MySQLi— 示例可以在PHP 手册中找到。

于 2012-12-30T18:35:49.293 回答