PHP
- 2 ответа
- 0 вопросов
1
Вклад в тег
<a href="delete.php?id=notesDelete=' . $row['id'] . '">
echo "<a href=delete.php?id=",$row['id'],"¬esDelete=1><button>delete</button></a>";
if (!isset($_GET['id'])) die("Error: not found id parameter");
$id = intval($_GET['id']);
if ($id == 0) die("Error: wrong id parameter value");
if (isset($_GET['notesDelete'])) {
$dbc = mysqli_connect('localhost', 'root', '', 'notes') or die('Connect error...');
$query = "DELETE FROM note WHERE id = ".$id;
$result = mysqli_query($dbc, $query);
mysqli_close($dbc);
} else {
die("Error: no any action found");
}
$id = intval("SELECT nothing"); var_dump($id);
$id = intval("1312; DELETE something"); var_dump($id);
$h = "DELETE FROM note WHERE id = '$id'";
var_dump($h);
$id = "10'; DROP DATABASE mysql; SELECT * FROM note WHERE id='1";
$h = "DELETE FROM note WHERE id = '$id'";
var_dump($h);
int(0)
int(1312)
string(34) "DELETE FROM note WHERE id = '1312'"
string(80) "DELETE FROM note WHERE id = '10'; DROP DATABASE mysql; SELECT * from note id='1'"