Example #1
0
$teacher = mysqli_real_escape_string($_POST["TEACHERID"]);
$destination = mysqli_real_escape_string($_POST["DESTINATION"]);
$time = mysqli_real_escape_string($_POST["TIMEOFPASS"]);
$date = mysqli_real_escape_string($_POST["DATEOFPASS"]);
$datetime = $date . " " . $time;
#EX:"2016-2-24 1:16:00";
/*$conn = mysqli_connect($servername,"root","");
if (!$conn) {
    die("connection error");
}
mysqli_select_db($conn,'dhp');
*/
$checkstudent = "SELECT `isTeacher` FROM " . $userDB . " WHERE ID = '" . $student . "'";
$ret = createQuery($checkstudent);
$row = mysqli_fetch_array($ret, MYSQLI_ASSOC);
if ($row['isTeacher'] != 'student') {
    die("Invalid student ID :" . $student);
}
$checkteacher = "SELECT `isTeacher`,`name` FROM " . $userDB . " WHERE ID = '" . $teacher . "'";
$ret = createQuery($checkteacher);
$row = mysqli_fetch_array($ret, MYSQLI_ASSOC);
if ($row['isTeacher'] != 'teacher') {
    die("Invalid teacher ID :" . $teacher);
}
$sql = "SELECT `ID` FROM " . $userDB . " WHERE name = '" . $row[name] . "'";
$ret = createQuery($sql);
$row2 = mysqli_fetch_arry($ret, MYSQLI_ASSOC);
$sql = "INSERT INTO " . $passDB . " (`ID`,`teacherName`,`dest`,`date`,`time`)\r\n        VALUES ('" . $student . "','" . $row2[name] . "','" . $destination . "','" . $date . "','" . $time . "')";
//mysqli_query($conn,$sql);
createQuery($sql);
//mysqli_close($conn);
<?php

session_start();
$server = "mysql.cs.iastate.edu:3306";
$serverUser = "******";
$serverPassword = "******";
$serverDatabase = "db30914";
$connection = msqli_connect($server, $serverUser, $serverPassword, $serverDatabase) or die("Could not connect.");
$output = "";
if (isset($_POST['search'])) {
    $search = $_POST['search'];
    $search = preg_replace("#[^0-9a-z]#i", " ", search);
    $query = mysqli_query($connection, "SELECT * FROM Activity WHERE content like '%{$search}%'") or die("Could not find search.");
    $count = mysql_num_rows($query);
    if ($count == 0) {
        $output = 'No result found.';
    } else {
        while ($row = mysqli_fetch_arry($query)) {
            $activityID = $row['activityID'];
            $content = $row['content'];
            $output .= '<div>' . $activityID . ' ' . $content . '</div>';
        }
    }
}
print_r("{$output}");