PDO预处理防sql注入

$pdo=new PDO('mysql:host=127.0.0.1;dbname=ci','root','root',array(PDO::MYSQL_ATTR_INIT_COMMAND=>'set names utf8'));
$arr=$pdo->prepare("insert into ceshi(ip,country,province,city,district,carrier)VALUE (?,?,?,?,?,?)");
$arr->bindParam(1,$ar['retData']['ip']);
$arr->bindParam(2,$ar['retData']['country']);
$arr->bindParam(3,$ar['retData']['province']);
$arr->bindParam(4,$ar['retData']['city']);
$arr->bindParam(5,$ar['retData']['district']);
$arr->bindParam(6,$ar['retData']['carrier']);
if($arr->execute()){
    echo "插入成功";
    echo "最后插入的ID:".$pdo->lastInsertId();
}else{
    echo "插入失败";
}
PDO预处理防sql注入_第1张图片

你可能感兴趣的:(PDO预处理防sql注入)