// Check connection
if (mysqli_connect_errno())
echo "Failed to connect to MySQL: " . mysqli_connect_error();
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<title>Search results</title>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<link rel="stylesheet" type="text/css" href="style.css"/>
$query = $_GET['query'];
// gets value sent over search form
$min_length = 3;
// you can set minimum length of the query if you want
if(strlen($query) >= $min_length){ // if query length is more or equal minimum length then
$query = htmlspecialchars($query);
// changes characters used in html to their equivalents, for example: < to >
$query = mysqli_real_escape_string($query);
// makes sure nobody uses SQL injection
$raw_results = mysqli_query($con,"SELECT * FROM test_table
WHERE ('email' LIKE '%".$query."%') OR ('pw' LIKE '%".$query."%')") or die(mysqli_error());
if(mysqli_num_rows($raw_results) > 0){ // if one or more rows are returned do following
echo "<table border='1'>
while($results = mysqli_fetch_array($raw_results)){
// $results = mysql_fetch_array($raw_results) puts data from database into array, while it's valid it does the loop
echo "<tr><td>".$results['email']."</td><td>".$results['pw']."</td></tr>";
//echo "<p><h3>".$results['email']."</h3>".$results['pw']."<br/>".$results['ID']."</p>";
else{ // if there is no matching rows do following
echo "No results";
else{ // if query length is less than minimum
echo "Minimum length is ".$min_length;
謝謝!這固定它......只要參數化查詢而不是轉義字符串,你有任何建議閱讀爲我學習如何做到這一點? –
@ user1958605 [This](http://www.dreamincode.net/forums/topic/54239-introduction-to-mysqli-and-prepared-statements/)是一個相當體面的快速入門,顯示了查詢的不同風格。 –