troubleshooting Question

Trying to prevent SQL Injection issues

Avatar of hrolsons
hrolsonsFlag for United States of America asked on
PHPMySQL Server
12 Comments1 Solution38 ViewsLast Modified:

I'm trying to prevent SQL injection issues.

I currently have:

$product_array = $db_handle->runQuery("SELECT photos_new.bookmark, photos_new.pic_online, photo_detail_new.ebay_title,15 AS price FROM photo_detail_new INNER JOIN photos_new ON photo_detail_new.bookmark = photos_new.bookmark  WHERE ebay_title like '%$fname%'");              

Open in new window

I have so far:

   $this->dbConn = $db_handle->connectDB();
   $product_array = $db_handle->prepare("SELECT photos_new.bookmark, photos_new.pic_online, photo_detail_new.ebay_title,15 AS price FROM photo_detail_new INNER JOIN photos_new ON photo_detail_new.bookmark = photos_new.bookmark  WHERE ebay_title like ?");                 
    $product_array->bind_param("s", $fname);     $product_array->execute();     $data = $product_array->get_result();     $product_array = mysqli_fetch_all($data, MYSQLI_ASSOC);     $st->close();

Open in new window

and it's not working.

I get:

Fatal error: Uncaught Error: Call to undefined method Hera\DBController::prepare() in /home/dh_95geeu/xxxxx.com/simple-shop/indexdetailnew.php:254 Stack trace: #0 {main} thrown in /home/dh_95geeu/xxxxx.com/simple-shop/indexdetailnew.php on line 254

Open in new window

ASKER CERTIFIED SOLUTION
gr8gonzo
Consultant

Our community of experts have been thoroughly vetted for their expertise and industry experience.

Log in to continue reading
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform for $9.99/mo
View membership options
Unlock 1 Answer and 12 Comments.
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
See how we're fighting big data
The Value of Experts Exchange in My Daily IT Life

Experts Exchange (EE) has become my company's go-to resource to get answers. I've used EE to make decisions, solve problems and even save customers. OutagesIO has been a challenging project and... Keep reading >>

Mike

Owner of Outages.IO
Phoenix, Arizona, United States
Member Since 2016
Join a full scale community that combines the best parts of other tools into one platform.
Unlock 1 Answer and 12 Comments.
View membership options
“All of life is about relationships, and EE has made a virtual community a real community. It lifts everyone's boat.”
William Peck

Member since 2004