1 回答

TA贡献1786条经验 获得超13个赞
尝试这个,
<?php
$stmt = $conn->prepare('SELECT * FROM stock WHERE amr_id = ?');
$stmt->bind_param('s', $searchkey); // 's' specifies the variable type => 'string'
$stmt->execute();
$result = $stmt->get_result();
$sum=0;
echo "<table id='customers' border='1' cellspacing='0' cellpadding='5' style='text-align:left;'><tr><th>Date</th><th>Rate Plan</th><th>Act</th><th>churn<th>Net</th></tr>";
while ($row = $result->fetch_assoc()) {
echo "<tr> <td>".$row["report_date"]."</td> <td> ".$row["rate_plan"]."</td> <td>".$row["act"]."</td><td>".$row["churn"]."</td><td>".$row["net"]."</td> </tr>";
$sum+=$row['act'];
}
echo $sum;
这应该是避免sql注入漏洞的方法
- 1 回答
- 0 关注
- 109 浏览
添加回答
举报