PHPize Online / SQLize Online  /  SQLtest Online

A A A
Share      Blog   Popular
Copy Format Clear
CREATE TABLE Employees (id int, name varchar(20)); INSERT INTO Employees (id, name) VALUES (1, 'Antonio'), (2, 'Antonio'), (3, 'Cezar'), (4, 'Wanderson'); SELECT * FROM Employees;
Copy Clear
Copy Format Clear
<?php $employee_id = '1'; $employee_id = explode(' ', $employee_id)[0]; $query = 'SELECT name FROM Employees WHERE id = CAST('.$employee_id.' AS INT)'; $stmt = $pdo->prepare($query); $stmt->execute(); $rows = $stmt->fetchAll(PDO::FETCH_ASSOC); var_dump($rows); echo PHP_EOL; $employee_id = '1/**/AS/**/INT)/**/OR/**/1=1/**/--'; #$employee_id = "1"; $employee_id = explode(' ', $employee_id)[0]; $query = 'SELECT name FROM Employees WHERE id = CAST('.$employee_id.' AS INT)'; echo $query.PHP_EOL; $stmt = $pdo->prepare($query); $stmt->execute(); $rows = $stmt->fetchAll(PDO::FETCH_ASSOC); var_dump($rows);
Show:  
Copy Clear