I am making a query like this:
$b1 = $_REQUEST['code'].'A'; //letter 'A' is concatenated to $_REQUEST['code']
$a = $_REQUEST['num'];
echo $b1.$a;
$sql = "SELECT '".$b1."' FROM student_record1 WHERE id=".$a;
$result = mysql_query($sql);
if(!$result)
{
echo '<p id="signup">Something went wrong.</p>';
}
else
{
$str = $row[0]
echo $str;
}
Here $b1 and $a are getting values from another page. The ‘echo’ in the third line is giving a correct result. And I am not getting any error in SQL. Instead, I am not getting any result from the SQL query. I mean echo at the last line.
Don’t do this, it breaks your relational model and is unsafe.
Instead of having a table with columns
ID,columnA,columnB,columnC,columnD,columnEand having the user selectA/B/C/D/Ewhich then picks the column, have a table with three columnsID,TYPE,columnand haveTYPEbeA/B/C/D/E. This also makes it easier to addF/G/H/Iafterwards without modifying the table.Secondly, with the extra column approach you don’t have to build your SQL from input values like that. You can use prepared statements, and be safe from SQL Injection. Building SQL from unfiltered strings is wrong, and very dangerous. It will get your site hacked.