显示提取时出错

问题描述 投票:0回答:1

在运行下面的代码片段时,我在所有行中的符号中获得相同的数字,但其他列不同。我希望他们所有人都不同

if($_POST['filter']>0 && $total<=totalRows($_POST['criteria'],$conn) && $total!=0)
                    {
                        $sql1="SELECT * FROM data AS d JOIN (SELECT ROUND(RAND() * (SELECT MAX(symbol) FROM data)) AS symbol ) AS x WHERE d.symbol >= x.symbol AND d.division = '".$_POST['criteria']."' LIMIT ".$total;
                        echo '<div style="width:725px; border: thin; padding-left: 7px;">
                        Total Column of '.getDivision($_POST['criteria']).':'.totalRows($_POST['criteria'],$conn).'
                            <div style="float: right; width: 300px;">
                                Selection<br>
                                Division: '.getDivision($_POST['criteria']).'<br>
                            </div><br>
                        Entered value: '.$_POST['filter'].' '.$_POST['type'].'<br>
                        In Number: '.$total.'<br><br>
                        SQL Syntax:<br><div style="padding-left:5px;">'.$sql1.'</div></div><br><br>';
                        $result1 = mysqli_query($conn, $sql1);
                        if (mysqli_num_rows($result1) > 0) {
                            while($val1 = mysqli_fetch_assoc($result1)) 
                            {
                                echo'<tr class="row100">
                                    <td class="column100 column1" data-column="column1">'.$val1['symbol'].'</td>
                                    <td class="column100 column2" data-column="column2">'.$val1['name'].'</td>
                                    <td class="column100 column3" data-column="column3">'.$val1['percent'].'</td>
                                    <td class="column100 column4" data-column="column4">'.getDivision($val1['division']).'</td>
                                </tr>';
                            }
                        }

编辑:在$ sql中使用以下内容并获得所需的输出

$sql1="SELECT * FROM data AS d JOIN (SELECT ROUND(RAND() * (SELECT 
MAX(symbol) FROM data)) AS id ) AS x WHERE d.symbol >= x.id AND d.division = 
'".$_POST['criteria']."' LIMIT ".$total;

php mysqli
1个回答
1
投票

欢迎使用sql注入2018请使用预处理语句,不要直接将用户值解析到您的查询中

无论如何你的子查询被缓存...你应该在php中执行你的rand()因为SQL_NO_CACHE不允许该子查询

© www.soinside.com 2019 - 2024. All rights reserved.