Jump to content

mysql_real_escape_string


RON_ron

Recommended Posts

I just red few tutorials about  mysql_real_escape_string. Could someone check if this is correct?

 

<?php
$conn = mysql_connect("localhost","myusername","thepassword1");
mysql_select_db("mydataB", $db);

$result = mysql_query("SELECT * FROM applicant WHERE username = '$username'");

if (mysql_num_rows ($result) > 0){
$register = "&err=Not Available.";
echo($register);
} else {
$username = mysql_real_escape_string($_POST['username'], $db);
$password = mysql_real_escape_string($_POST['password'], $db);
$name = mysql_real_escape_string($_POST['name'], $db);
$email = mysql_real_escape_string($_POST['email'], $db);
$id = mysql_real_escape_string($_POST['id'], $db);

mysql_query("INSERT INTO applicant (username, password, name, email, id) VALUES ('$username', '$password', '$name', '$email', '$id')");
$register = "Successful.";
echo($register);
}
?>

Link to comment
Share on other sites

For the } else { // real escapre string } part it is ok.

 

But after the mysql_select_db(), you have $username not escaped.

<?php
$conn = mysql_connect("localhost","myusername","thepassword1");
mysql_select_db("mydataB", $db);

// Escape special characters
$username = mysql_real_escape_string($_POST['username'], $db);
// Then use the escaped $username
$result = mysql_query("SELECT * FROM applicant WHERE username = '$username'");

if (mysql_num_rows ($result) > 0){
$register = "&err=Not Available.";
echo($register);
} else {
$username = mysql_real_escape_string($_POST['username'], $db);
$password = mysql_real_escape_string($_POST['password'], $db);
$name = mysql_real_escape_string($_POST['name'], $db);
$email = mysql_real_escape_string($_POST['email'], $db);
$id = mysql_real_escape_string($_POST['id'], $db);

mysql_query("INSERT INTO applicant (username, password, name, email, id) VALUES ('$username', '$password', '$name', '$email', '$id')");
$register = "Successful.";
echo($register);
}
?>

 

Besides that, the link identiefier would be $conn here, i dont know why you are using $db as link ID.

Link to comment
Share on other sites

I'm getting some errors.

 

Warning: mysql_select_db(): supplied argument is not a valid MySQL-Link resource in /home/.../test.php on line 3

 

Warning: mysql_real_escape_string() expects parameter 2 to be resource, null given in /home/.../test.php on line 5

 

Warning: mysql_num_rows(): supplied argument is not a valid MySQL result resource in /home/.../test.php on line 8

 

Link to comment
Share on other sites

<?php
$conn = mysql_connect("localhost","myusername","thepassword1");
mysql_select_db("mydataB", $conn);

// Escape special characters
$username = mysql_real_escape_string($_POST['username'], $conn);
// Then use the escaped $username
$result = mysql_query("SELECT * FROM applicant WHERE username = '$username'");

if (mysql_num_rows($result) > 0){
$register = "&err=Not Available.";
echo($register);
} else {
$username = mysql_real_escape_string($_POST['username'], $conn);
$password = mysql_real_escape_string($_POST['password'], $conn);
$name = mysql_real_escape_string($_POST['name'], $conn);
$email = mysql_real_escape_string($_POST['email'], $conn);
$id = mysql_real_escape_string($_POST['id'], $conn);

mysql_query("INSERT INTO applicant (username, password, name, email, id) VALUES ('$username', '$password', '$name', '$email', '$id')");
$register = "Successful.";
echo($register);
}
?>

Link to comment
Share on other sites

It actually doesn't update my db.

 

intellix

print "$username ";
$username = mysql_real_escape_string($_POST['username'], $conn);
$result = mysql_query("SELECT * FROM applicant WHERE username = '$username'");
print "$username ";

 

before : shows the username

after: nothing

Link to comment
Share on other sites

<?php

$conn = mysql_connect("localhost","myusername","thepassword1");

mysql_select_db("mydataB", $conn);

 

$username = mysql_real_escape_string($_POST['username'], $conn);

$result = mysql_query("SELECT * FROM applicant WHERE username = '$username'");

 

if (mysql_num_rows($result) > 0){

$register = "&err=Not Available.";

echo($register);

} else {

$username = mysql_real_escape_string($_POST['username'], $conn);

$password = mysql_real_escape_string($_POST['password'], $conn);

$name = mysql_real_escape_string($_POST['name'], $conn);

$email = mysql_real_escape_string($_POST['email'], $conn);

$id = mysql_real_escape_string($_POST['id'], $conn);

 

mysql_query("INSERT INTO applicant (username, password, name, email, id) VALUES ('$username', '$password', '$name', '$email', '$id')");

$register = "Successful.";

echo($register);

}

?>

Link to comment
Share on other sites

This thread is more than a year old. Please don't revive it unless you have something important to add.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.