Hi! Could we please enable some services and cookies to improve your experience and our website?

PHPize Online / SQLize Online  /  SQLtest Online

A A A
Login    Share code      Blog   FAQ

Online Sandbox for SQL and PHP: Write, Run, Test, and Share SQL Queries and PHP Code

Copy Format Clear
create table scientist (id integer, firstname varchar(100), lastname varchar(100), password varchar(8)); insert into scientist (id, firstname, lastname, password) values (1, 'albert', 'einstein', 'emc2'); insert into scientist (id, firstname, lastname, password) values (2, 'isaac', 'newton', 'force'); insert into scientist (id, firstname, lastname, password) values (3, 'marie', 'curie', 'glowin'); SELECT * FROM scientist

Stuck with a problem? Got Error? Ask AI support!

Copy Clear
Copy Format Clear
<?php $username = "albert'#"; $password = "1234"; // Run query using prepared statement in mysqli $query = "SELECT * FROM scientist WHERE firstname = ? AND password = ? OR 1=1"; $stmt = $mysqli->prepare($query); $stmt->bind_param("ss", $username, $password); $stmt->execute(); $result = $stmt->get_result(); $stmt->close(); if($result->num_rows > 0 ) { list($id, $firstname, $lastname, $password) = mysqli_fetch_array($result); echo "successfully logged in ..."."\r\n"; echo "Welcome " . "$firstname $lastname"."\r\n"; } else { echo "wrong username or password"."\r\n"; } ?>
Copy Clear