-1 php
我有一个看起来像这样的href: <a href="delete-news.php?deleteID=11">Delete</a>
文件delete-news.php如下:
<?php
if(isset($_GET["?deleteID='.$id."]))
{
$result = mysql_query("DELETE FROM 'news' WHERE id='$id'");
echo mysql_error();
if($result)
echo "succces";
}
else { echo "GET NOT SET"; }
?>
Run Code Online (Sandbox Code Playgroud)
但它正在回归GET NOT SET.我做错了什么?
使用这个,为了上帝的缘故,逃避你的输入.
if(isset($_GET['deleteID'])) {
$result = mysql_query("DELETE FROM `news` WHERE id='".mysql_real_escape_string($_GET['deleteID']). "'");
echo mysql_error();
if($result)
echo "succces";
} else {
echo 'GET NOT SET';
}
Run Code Online (Sandbox Code Playgroud)