<?php$str1="SDM";echo"ord(): ".ord($str1)."</br>";echo"chr(): ".chr(83)."</br>"."</br>";$str2="SDM--你好啊";echo"urlencode(): ".urlencode($str2)."</br>";echo"urldecode(): ".urldecode('SDM--%E4%BD%A0%E5%A5%BD%E5%95%8A')."</br>"."</br>";$str3="这是一段测试文本";echo"base64_encode:".base64_encode($str3)."</br>";echo"base64_decode:".base64_decode('6L+Z5piv5LiA5q615rWL6K+V5paH5pys')."</br>"."</br>";$str4="This is some <b>bold</b> text.";echo"htmlspecialchars:".htmlspecialchars($str4)."</br>";echo"htmlspecialchars_decode:".htmlspecialchars_decode($str4)."</br>"."</br>";$str5="hello world!";echo"str_replace:".str_replace("hello","My",$str5)."</br>"."</br>";$str6="SDM_MD5";echo"md5:".md5($str6)."</br>";?>
<?phpif(!$connect=mysqli_connect('localhost','root','123456')){die('erro!');}if(!$flag1=mysqli_select_db($connect,'SDM')){echo'connect fail!'."</br>";}if(!$flag2=mysqli_query($connect,"insert into teacher (id,name,addr) values (1,'SDM','xiamen')")){echo'insert fail!'."</br>";}if($result=mysqli_query($connect,"select * from teacher")){while($row=mysqli_fetch_array($result)){echo$row['id']." ".$row['name']." ".$row['addr'];echo"</br>";}}mysqli_close($connect);?>
4)绑定参数防SQL注入
创建一个php文件,输入如下代码:
<?phpif(!$connect=mysqli_connect('localhost','root','123456')){die('erro!');}if(!$flag2=mysqli_select_db($connect,'SDM')){echo'connect fail!'."</br>";}$sql='select * from teacher where id = ?';$id=$_GET['id'];if($stmt=mysqli_prepare($connect,$sql)){mysqli_stmt_bind_param($stmt,'s',$id);mysqli_stmt_execute($stmt);mysqli_stmt_bind_result($stmt,$id,$name,$addr);while(mysqli_stmt_fetch($stmt)){printf("%d %s %s </br>",$id,$name,$addr);}}mysqli_stmt_close($stmt);mysqli_close($connect);?>