Welcome to collectivesolver - Programming & Software Q&A with code examples. A website with trusted programming answers. All programs are tested and work.

Contact: aviboots(AT)netvision.net.il

Buy a domain name - Register cheap domain names from $0.99 - Namecheap

Scalable Hosting That Grows With You

Secure & Reliable Web Hosting, Free Domain, Free SSL, 1-Click WordPress Install, Expert 24/7 Support

Semrush - keyword research tool

Boost your online presence with premium web hosting and servers

Disclosure: My content contains affiliate links.

39,870 questions

51,793 answers

573 users

How to run SQL query on MySQL with PHP Data Objects (PDO) for increased security in PHP

1 Answer

0 votes
$db_host = 'localhost';
$db_user = 'user';
$db_password = 'password';
$db_name = 'database_name';
 
try
{
    $con = new PDO("mysql:host=".$db_host.";dbname=".$db_name, $db_user, $db_password);
}
catch(PDOException $e)
{
    echo "Connection failed: " . $e->getMessage();
}
 
$result = $con->prepare("SELECT user_id, firstname, lastname, email
                         FROM wf_users
                         WHERE email = :email
                         AND password = :password");  

$result->bindParam(':email', $_POST['email'], PDO::PARAM_STR);
$result->bindParam(':password', $_POST['password'], PDO::PARAM_STR);

$result->execute();
                
$row = $result->fetch(PDO::FETCH_ASSOC); // get the first row only

echo $row['email'];

// if it didn't work - check for errors with:
$r = $result->errorInfo();
echo $r;

// if $r is:
/*
: array = 
  0: string = "00000"
  1: undefined = NULL
  2: undefined = NULL
*/
// then the query run without errors


answered May 25, 2015 by avibootz
edited May 25, 2015 by avibootz
...