if(!$db) {
echo 'ERROR: Could not connect to the database.';
} else {
if(isset($_POST['queryString'])) {
$queryString = $_POST['queryString'];
if(strlen($queryString) > 0) {
$query = $db->query("SELECT name FROM MS_store WHERE name LIKE '$queryString%' LIMIT 10");
if($query) {
while ($result = $query->fetch_object()) {
echo '</li><li onclick="fill(''.$result->value.'');
">'.$result->value.'</li>';
}
} else {
echo 'ERROR: There was a problem with the query.';
}
} else {
}
} else {
echo 'There should be no direct access to this script!';
}
}
if(isset($_POST['queryString'])) {
if( array_key_exist( 'queryString', $_POST)) {
$query = $db->query("SELECT name FROM MS_store WHERE name LIKE '$queryString%' LIMIT 10");
инъекцияecho '</li><li onclick="fill(''
echo "</li><li onclick=\"fill( '{$result->value}');\">{$result->value}</li>";
хотя бы так