使用sprintf函数注入动态sql
$query = sprintf("
SELECT
tagging_id, tagging_name
FROM
%sfaqtags
%s
ORDER BY tagging_name",
SQLPREFIX,
(isset($search) && ($search != '') ? "WHERE tagging_name ".$like." '".$search."%'" : '')
);
$query = sprintf("
SELECT
tagging_id, tagging_name
FROM
%sfaqtags
%s
ORDER BY tagging_name",
SQLPREFIX,
(isset($search) && ($search != '') ? "WHERE tagging_name ".$like." '".$search."%'" : '')
);
401

被折叠的 条评论
为什么被折叠?



