如何在select where参数中使用echo


how to use the echo in select where parameter?

我想使用字符串(echo$row['en'];)在主题的where参数中的select命令中:

$sql="SELECT * FROM uploaded WHERE sbid='".$newid."' AND subject = **HERE** ;

感谢:)

您可以像这样构建SQL查询:

$sql = "SELECT * FROM uploaded WHERE sbid = $newid AND subject = '{$row['en']}'";

然而,像这样构建SQL查询通常是不安全的,因为它可能会受到SQL注入的攻击。