-4

这是我的代码:

<?php
    $_SETTINGS = $GLOBALS["_SETTINGS"];
    $trigger = $_SETTINGS->fields->trigger->value;
    echo $trigger . " = " . $_GET[$trigger] . "</br>";
    $townQry = "SELECT * FROM towns WHERE id = '" . $_GET[$trigger] . "'";
    echo $townQry . "</br>";
    $result = mysql_query($cityQry) or die('Could not retreive towns: ' . mysql_error());

    while ($town = mysql_fetch_assoc($result)) {
        echo $town["town_name"];
    }
?>

这就是它的回声:

town_id = 2
SELECT * FROM towns WHERE id = '2'
Could not retreive towns: Query was empty

SQL 不是有效的...!?

4

2 回答 2

3

$cityQry在查询中使用,但查询在$townQry.

$result = mysql_query($townQry) or die('Could not retreive towns: ' . mysql_error());

额外的

您的查询对 sql 注入开放,我建议您使用 Google 准备好的语句。

于 2013-06-07T18:54:38.307 回答
1

您正在调用查询:

mysql_query($cityQry)

但是您的查询变量名为$townQuery.

它应该是:

mysql_query($townQuery)
于 2013-06-07T18:54:44.613 回答