不能插入数据,只是一个我的mysql表


cant insert data to just one of my mysql table

我正在开发网站,有趣的是,我可以将数据插入到所有表中,除了我的一个表。

PHP部分

function newproperty(){
    global $link;
    if(isset($_POST['sendprop']) && $_POST['agree'] == 'Yes'){
        $name=mysqli_real_escape_string($link,$_POST['name']);
        $owner=mysqli_real_escape_string($link,$_POST['owner']);
        $tel=mysqli_real_escape_string($link,$_POST['tel']);
        $email=$_SESSION['cust_user'];
        $type=$_POST['type'];
        $loc=$_POST['location'];
        $address=mysqli_real_escape_string($link,$_POST['address']);
        $bed=$_POST['bed'];
        $price=$_POST['price'];
        $descrip=mysqli_real_escape_string($link,$_POST['desc']);     
        $temp = explode(".", $_FILES["pic"]["name"]);
        $thumb = round(microtime(true)) . '.' . end($temp);
        move_uploaded_file($_FILES["pic"]["tmp_name"], 'assets/propthumb/'.$thumb); 
        $query="insert into property 
                (prop_name, prop_email, prop_owner, 
                 prop_tel, prop_type, prop_location, 
                 prop_bed, prop_price, prop_thumb, 
                 prop_desc, prop_address) 
                values 
                  ('$name','$email','$owner',
                   '$tel','$type','$loc',
                   '$bed','$price','$thumb',
                   '$descrip','$address')";
        $run=mysqli_query($link,$query);
        if($run){
            echo"<script>alert('Property has been inserted successfully');</script>";
            echo"<script>window.open('list.php','_self');</script>";
        }
   }
}
<<p> HTML部分/strong>
<form action="submit.php" method="post" enctype="multipart/form-data">
<div class="container bgsearch shadow">
    <div class="container-fluid ">
        <br>
        <div class="row">
            <div class="col-lg-10 col-lg-offset-1">
                <img src="assets/images/hero1.png" class=" img-responsive">
            </div>
        </div>
        <div class="row">
            <div class="col-lg-8 col-lg-offset-2">
                <h3 class="wtxt text-center">Submit Property</h3>
                <br>
                <hr id="hr">
            </div>
        </div>
        <div class="row">
            <div class="col-lg-6 col-lg-offset-3">
                <a href="list.php" class="form-control btn btn-success btn-block">List of my properties</a>
                <br>
            </div>
        </div>
        <div class="row">
            <div class="col-lg-2"></div>
            <div class="col-lg-4">
                <input type="text" class="form-control btn-block" name="name" placeholder="Property Name">
                <input type="text" class="form-control btn-block" name="owner" placeholder="Owner Name">
                <input type="tel" class="form-control btn-block" name="tel" placeholder="Owner Telephone Number">
                <select class=" btn-block form-control" name="type" required>
                    <option value='...'>...</option>
                </select>
                <select class=" btn-block form-control" name="location" required>
                    <option value='...'>...</option>
                     .
                </select>
                <input type="text" class="form-control btn-block" name="address" placeholder="Address">
                <input type="number" name="bed" class=" btn-block form-control" placeholder="Bedroom" min="0">
            </div>
            <div class="col-lg-4">
                <input type="number" name="price" class=" btn-block form-control" placeholder="Price (TL)" step="25" min="200">
                <lable class="wtxt"><h5><b>Property Thumbnail Image</b></h5></lable>    
                <input type="file" class="form-control btn-block" name="pic" accept="image/*">
                <textarea class="form-control btn-block" name="desc" rows="6" required></textarea>
                <div class="checkbox">
                    <label>
                        <input type="checkbox" name="agree" value="Yes"> Agree With Terms &amp; Conditions 
                    </label>
                </div>
            </div>
            <div class="col-lg-2"></div>
        </div>
        <div class="row">
            <div class="col-lg-8 col-lg-offset-2">
                <input type="submit" class="form-control btn btn-warning btn-block" name="sendprop" value="Submit">
            </div>
        </div>
        <br><br>
    </div>
</div>
</form>
<?php newproperty(); ?>

我尝试过但仍然不起作用的是:1. 删除表格并创建新表格2. 更改表的名称3.把insert改成…要插入的值。集……4。…

请尽快帮助我。

处理错误条件,例如

    if($run){
        // whatever
    } else {
        echo "<script>alert('SQL error: " 
           . htmlspecialchars(mysqli_error($link))
           . "');</script>"
    }

为了找出语句不工作的原因,为了调试,发出SQL文本并在不同的客户端中测试。


你在某些值上调用mysqli_real_escape_string函数,而不是在其他值上。因此,您的SQL INSERT语句仍然容易受到SQL注入的攻击。

一个更好的模式是使用准备好的语句绑定占位符。其实没那么难。