Jestli muzes kdyz se podivas na nize uvedeny kod kde vidis bezpecnostni trhlinu a jak ji osetrit?
function OpenMyDBCl()
{
try {
$dbh = new PDO("mysql:host=host;dbname=tarzan", "databaze", "heslo"); //
$GLOBALS ['$dbh']=$dbh;
} catch (PDOException $e) { // if not get the messagge
print "<h3 class='bmessage'>Failed to connect to MySql</h3> " . "<br/>" . $e->getMessage() ;
require ('template/footer.phtml');
die();
}
}
Na jine strance nactu require ("connect.php");
OpenMyDBCl();
$dbhselect=$GLOBALS ['$dbh'];
$sqlselect = 'SELECT * FROM my_address ORDER BY surname DESC';
$resultsselect = $dbhselect->prepare($sqlselect);
$resultsselect->execute();
<?php while($row = $resultsselect->fetch()){
Echo $row['surname'];
}