Sql注入源码 --- mysql

    header("content-type:text/html;charset=UTF-8");

    $id = $_GET['id'];

    $conn = mysql_connect('127.0.0.1','root','root') or die("could not connect:".mysql_error());    ##数据库连接

    mysql_select_db('test',$conn) or die('can not use:'.mysql_error());

    $sql = "select * from guestbook where comment_id='{$id}'";    

    $cun = mysql_query($sql) or die(mysql_error());

    echo "

回显:


";

    while($row = mysql_fetch_array($cun)){

        echo "标题:".$row['name']."
";

        echo "内容:".$row['comment']."
";

        echo "


";

    };

    mysql_close($conn);

    echo "您当前执行的SQL语句:";

    echo urldecode($sql);

?>

你可能感兴趣的:(Sql注入源码 --- mysql)