SitePoint Sponsor

User Tag List

Results 1 to 4 of 4
  1. #1
    SitePoint Addict
    Join Date
    Jun 2007
    Location
    Plymouth uk
    Posts
    313
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    help needed to get this slide show to work

    ok i have this slide show which works when a folder addy is put in
    but i am trying to use a variable but dosnt work if some one could have a look
    cheers
    Doug

    Code:
    imgAr1[0] = "http://www.djbcaravanhire.co.uk/show/".$info['pname'] . " /1.jpg";
    do i have to run mysql before this

    PHP Code:
    <?php

    $id 
    $_GET["id"];
    // Connects to your Database 
     
    $dbh=mysql_connect("localhost""vcd""57") or die('I cannot connect to database because: ' .mysql_error()) ; 
    mysql_select_db("users"); 
     
    //Retrieves data from MySQL
      
    $data mysql_query("SELECT * FROM members WHERE username='$id'") or die(mysql_error());

    //Puts it into an array 
    while($info mysql_fetch_array$data )) 

    $count $info['enq'] ;
    //Outputs the image and other data
    Echo "<b>Available for:</b> ".$info['region'] . "<br>";
    Echo 
    "<b>Name:</b> ".$info['name'] . " <br>";
    Echo 
    "<b>Contact:</b> ".$info['contact'] . " <br>";
    Echo 
    "<b>Park Name:</b> ".$info['parkname'] . " <br>";
    Echo 
    "<b>County:</b> ".$info['county'] . " <br>";
    Echo 
    "<b>Park Location:</b> ".$info['parklocation'] . " <br>";
    Echo 
    "<b>Details:</b> ".$info['caravandetails'] . " <br>";
    Echo 
    "<b>Smoking:</b> ".$info['smoke'] . " <br>";
    Echo 
    "<b>Pets:</b> ".$info['pets'] . " <br>";
    Echo 
    "<b>Children:</b> ".$info['kids'] . " <br>";
    Echo 
    "<b>Same sex groups:</b> ".$info['sex'] . " <br>";
    }

    ?>
    cheers
    Doug
    Last edited by dougvcd; Sep 2, 2008 at 09:04. Reason: more code added
    an old man of 60 trying to keep up with the youngsters he he
    http://lostpetsplymouth.net16.net

  2. #2
    SitePoint Addict
    Join Date
    Dec 2007
    Posts
    358
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    1. You have SQL injection vulnerability in your code. Escape the $id variable before adding it to the query.
    2. It seems that you have extra space in your code:
    Code:
    co.uk/show/".$info['pname'] . "HERE> <HERE/1.jpg";
    3. "Echo" is quite strange in PHP... use "echo".
    I'm creating trouble-free Apache, PHP, MySQL installer, WITSuite,
    and use it to setup my development environment.
    Demo, support, contact. Questions?

  3. #3
    SitePoint Addict
    Join Date
    Jun 2007
    Location
    Plymouth uk
    Posts
    313
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    no that did not work
    back to drawing board
    cheers
    Doug
    an old man of 60 trying to keep up with the youngsters he he
    http://lostpetsplymouth.net16.net

  4. #4
    SitePoint Enthusiast snajt's Avatar
    Join Date
    May 2008
    Location
    Kalmar, Sweden
    Posts
    45
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Hi,

    the $info["pname"] does only exists inside the while-statement, so you have to put it in there. If that's not a reasonable solution please give us a more details about what you're want to achieve.


Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •