2017-04-02 49 views
-2

我有一种形式,需要从变量另一种形式,像这样:使用变量PHP SQL更新发布到形式

$employeeid = $_POST['modifyid']; 
$fname = $_POST['modifyfn']; 
$lname = $_POST['modifyln']; 
$staffno = $_POST['modifysn']; 
$empusername = $_POST['modifyeu']; 

</br> 
<td><form action="empmodify.php" method="post"> 
    <?php echo 
    "<div class='form-group'> 
      <tr><td>ID:</td><td> 
       <input type='text' class='form-control' name='modid' value='" . $employeeid . "'/> 
      </td></tr> 
     </div> 

    <div class='form-group'> 
      <tr><td>First Name:</td><td> 
       <input type='text' class='form-control' name='modfn' value='" . $fname . "'/> 
      </td></tr> 
     </div> 

     <div class='form-group'> 
      <tr><td>Surname Name:</td><td> 
       <input type='text' class='form-control' name='modln' value='" . $lname . "'/> 
      </td></tr> 
     </div> 

     <div class='form-group'> 
      <tr><td>Staff number:</td><td> 
       <input type='text' class='form-control' name='modsn' value='" . $staffno . "'/> 
      </td></tr> 
     </div> 

     <div class='form-group'> 
      <tr><td>Username:</td><td> 
       <input type='text' class='form-control' name='modeu' value='" . $empusername . "'/> 
      </td></tr> 
     </div> 


    <button type='submit' class='btn btn-default'>Modify this Employee</button>"?> 
      </form></td> 

    </div> 

这些变量已经在数据库中 - 这部分工作。我想要的是,当用户点击提交时,它会更新记录,并在此表单中更改其中的任何内容。这里是我的empmodify.php:

$employeeid = $_POST['modid']; 
    $fname = $_POST['modfn']; 
    $lname = $_POST['modln']; 
    $staffno = $_POST['modsn']; 
    $empusername = $_POST['modeu']; 


    $result = mysql_query("UPDATE employee SET fname = '$fname', lname = '$lname', staffno = '$staffno', empusername = '$empusername' WHERE employeeid = '$employeeid'"); 

我已经尝试了这么多的事情与我的变量,但update语句似乎并不奏效。我试过单引号,双引号,发帖,并连接它们,但没有任何想法? :)

+0

做你尝试调试它? – Ravi

+0

检查$ _POST的真实内容.. var_dump($ _ POST).. – scaisEdge

+0

我明白了!谢谢你 – sd0093

回答

-1

尝试用这样的事情:

$result = mysql_query('UPDATE employee SET fname = "'.$fname.'", lname = "'.$lname.'", staffno = "'.$staffno.'", empusername = "'.$empusername.'" WHERE employeeid = "'.$employeeid.'"'); 
+0

这工作!谢谢:) – sd0093

+0

你知道我是否可以使用这种方法更新密码? – sd0093

+0

[Little Bobby](http://bobby-tables.com/)说*** [你的脚本存在SQL注入攻击风险。](http://stackoverflow.com/questions/60174/how-can- I-防止-SQL注入式-PHP)***。即使[转义字符串](http://stackoverflow.com/questions/5741187/sql-injection-that-gets-around-mysql-real-escape-string)是不安全的! –