Solved

Select rows that contain a specific word (mysql - php)

Posted on 2009-07-10
5
267 Views
Last Modified: 2012-05-07
Hi E's, snippet code contain the code I use to find rows that = $ppp. This code just word when $ppp is exact match of assoc_simultaneo contain.
If the contain of assoc_simultaneo was "one two five twenty" and if $ppp was = "five", the row is not selected. The row was selected if $ppp was = "one two five twenty".
What I want is if $ppp contain one of the words of assoc_simultaneo, the row will be selected. I try to change '$ppp' to '%$ppp%', but don't word.

What changes I have to in my code?

Regards, JC

$assoc_result = mysql_query("SELECT * FROM keywords where assoc_simultaneo = '$ppp'", $db);
$assoc_rows = mysql_num_rows($assoc_result);
$assoc = mysql_fetch_object($assoc_result);

Open in new window

0
Comment
Question by:Pedro Chagas
5 Comments
 
LVL 8

Accepted Solution

by:
stefanx earned 125 total points
ID: 24827879
$assoc_result = mysql_query("SELECT * FROM keywords where assoc_simultaneo LIKE '%$ppp%'", $db)
0
 
LVL 28

Assisted Solution

by:gamebits
gamebits earned 125 total points
ID: 24827884
mysql_query("SELECT * FROM keywords where assoc_simultaneo LIKE '%$ppp%'", $db);
0
 
LVL 34

Expert Comment

by:gr8gonzo
ID: 24828028
In case nobody's said this before, it's good programming practice to always sanitize any variables that are used in queries. For example, if $ppp is provided by a user coming to a web page and typing in something to search for, then a user could search for:

%';DROP TABLE keywords;SELECT * FROM whatever WHERE blah LIKE '%

Then, when the query runs, it would execute this query:

$assoc_result = mysql_query("SELECT * FROM keywords where assoc_simultaneo LIKE '%%';DROP TABLE keywords;SELECT * FROM whatever WHERE blah LIKE '%%'", $db);

MySQL isn't smart enough to catch that type of stuff, so it would just run three queries:
SELECT * FROM keywords where assoc_simultaneo LIKE '%%';
DROP TABLE keywords;
SELECT * FROM whatever WHERE blah LIKE '%%';

Presto, the user has just deleted your entire keywords table. It's called SQL injection and there are a lot of articles out on the web on how to prevent this type of thing.

This is just for educational purposes - stefanx and gamebits gave you good answers.
0
 
LVL 34

Expert Comment

by:gr8gonzo
ID: 24828037
I guess you awarded the points while I was writing that up, so ignore the last line. It made more sense when you hadn't awarded the points yet. :)
0
 
LVL 3

Author Comment

by:Pedro Chagas
ID: 24828254
Thanks @gr8gonzo.
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Using SQL Scripts we can save all the SQL queries as files that we use very frequently on our database later point of time. This is one of the feature present under SQL Workshop in Oracle Application Express.
Load balancing is the method of dividing the total amount of work performed by one computer between two or more computers. Its aim is to get more work done in the same amount of time, ensuring that all the users get served faster.
The viewer will learn how to count occurrences of each item in an array.
Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…

810 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question