$teacher = mysqli_real_escape_string($_POST["TEACHERID"]); $destination = mysqli_real_escape_string($_POST["DESTINATION"]); $time = mysqli_real_escape_string($_POST["TIMEOFPASS"]); $date = mysqli_real_escape_string($_POST["DATEOFPASS"]); $datetime = $date . " " . $time; #EX:"2016-2-24 1:16:00"; /*$conn = mysqli_connect($servername,"root",""); if (!$conn) { die("connection error"); } mysqli_select_db($conn,'dhp'); */ $checkstudent = "SELECT `isTeacher` FROM " . $userDB . " WHERE ID = '" . $student . "'"; $ret = createQuery($checkstudent); $row = mysqli_fetch_array($ret, MYSQLI_ASSOC); if ($row['isTeacher'] != 'student') { die("Invalid student ID :" . $student); } $checkteacher = "SELECT `isTeacher`,`name` FROM " . $userDB . " WHERE ID = '" . $teacher . "'"; $ret = createQuery($checkteacher); $row = mysqli_fetch_array($ret, MYSQLI_ASSOC); if ($row['isTeacher'] != 'teacher') { die("Invalid teacher ID :" . $teacher); } $sql = "SELECT `ID` FROM " . $userDB . " WHERE name = '" . $row[name] . "'"; $ret = createQuery($sql); $row2 = mysqli_fetch_arry($ret, MYSQLI_ASSOC); $sql = "INSERT INTO " . $passDB . " (`ID`,`teacherName`,`dest`,`date`,`time`)\r\n VALUES ('" . $student . "','" . $row2[name] . "','" . $destination . "','" . $date . "','" . $time . "')"; //mysqli_query($conn,$sql); createQuery($sql); //mysqli_close($conn);
<?php session_start(); $server = "mysql.cs.iastate.edu:3306"; $serverUser = "******"; $serverPassword = "******"; $serverDatabase = "db30914"; $connection = msqli_connect($server, $serverUser, $serverPassword, $serverDatabase) or die("Could not connect."); $output = ""; if (isset($_POST['search'])) { $search = $_POST['search']; $search = preg_replace("#[^0-9a-z]#i", " ", search); $query = mysqli_query($connection, "SELECT * FROM Activity WHERE content like '%{$search}%'") or die("Could not find search."); $count = mysql_num_rows($query); if ($count == 0) { $output = 'No result found.'; } else { while ($row = mysqli_fetch_arry($query)) { $activityID = $row['activityID']; $content = $row['content']; $output .= '<div>' . $activityID . ' ' . $content . '</div>'; } } } print_r("{$output}");