RE: [PHP-DB] Re: session variable in select query showing picture from database

[email protected] ("Fortuno, Adam")
Newsgroups php.db
Message-ID <CED447ECB4C001419947EBF4776E503203EA74DC@ghrintallmsg2.CORPORATE.GHRSYS.AD>
Mika,

Echo out the dynamically created SQL statement ie., $query = "SELECT *
FROM MyTable WHERE ID = ${ID}"; ECHO $query;" Let us see what is
actually being passed.

P.S. I couldn't agree more with the poster that said, don't pass user
input directly to a SQL statement.

-----Original Message-----
From: Mika Jaaksi [mailto:[email protected]] 
Sent: Thursday, February 12, 2009 5:02 PM
To: [email protected]
Subject: [PHP-DB] Re: session variable in select query showing picture
from database

*Answer to Rick:

in your code below it looks like you're simply hard-coding your
"$band_id" value (as "11") -- so of course it's going to work.

*Yes, I did that because one of you helpers asked me to try that.

I'll try to be clearer on whom I'm answering to...
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.