【发布时间】:2018-05-13 19:29:06
【问题描述】:
我正在实现一个简单的代码来检查一封电子邮件是否已经在我的数据库中,以及它是否正在从数据库中删除它。但是,我收到此错误消息:
Fatal error: Uncaught PDOException: SQLSTATE[42000]: Syntax error or access
violation: 1064 You have an error in your SQL syntax; check the manual that
corresponds to your MySQL server version for the right syntax to use near
'@gmail.com' at line 1 in /home/saintpao/public_html/deleteNewsletter.php:24 Stack
trace: #0 /home/saintpao/public_html/deleteNewsletter.php(24):
PDOStatement->execute() #1 {main} thrown in /home/saintpao/public_html
/deleteNewsletter.php on line 24
这是conectar.php 文件
$dbhost = "myHost";
$dbuser = "myUser";
$dbpass = "myPassword";
$dbname = "myDBName";
try {
$db = new PDO("mysql:host=$dbhost;dbname=$dbname", $dbuser, $dbpass,
array(PDO::MYSQL_ATTR_INIT_COMMAND => "SET NAMES 'UTF8'"));
$db->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION);
}catch(Exception $error) {
die("Error conexión BBDD " . $error->getMessage());
}
这是deleteNewsletter.php 文件:
function sanitazeEmail($email){
if(empty($email)){
return "";
}
$sanitized = filter_var($email, FILTER_SANITIZE_EMAIL);
if(filter_var($sanitized, FILTER_VALIDATE_EMAIL)){
return $sanitized;
}
return "";
}
$success = false;
$email = sanitazeEmail($_POST['email']);
if(!empty($email)){
require_once 'conectar.php';
$sql = "SELECT `email` FROM `emails` WHERE `email` = " . $email;
$statement = $db->prepare($sql);
if($statement->execute()){
$sql_delete = "DELETE FROM `emails` WHERE `email` =" . $email;
$statement = $db->prepare($sql_delete);
$success = $statement->execute();
}
}
与数据库的连接有效,因为我可以在其他文件中进行 SELECT 请求,所以deleteNewsletter.php 文件肯定有问题。知道有什么问题吗?
【问题讨论】:
-
将文字文本添加到作为字符串的 SQL 语句时,您需要在它们周围加上引号。
-
了解prepared statements以防止sql注入
-
添加以下行是否足以避免 SQL 注入?
$statement->bindParam(':email', $email); -
@Jens 忘了在最后一条评论中引用你的内容
标签: php mysql sql database pdo