xss-1
";
if(isset($_GET['id'])) {
$id = $_GET['id'];
echo "传入的值:id=" .$id;
echo "
";
$sql_query="SELECT * FROM users WHERE id='$id' LIMIT 0,1";
print_r("$sql_query");
echo "
";
$result = mysql_query($sql_query);
$arr = mysql_fetch_array($result);
if ($arr) {
echo "
";
echo "
";
echo "Username: " .$arr['username'];
echo "
";
echo "Password: " .$arr['password'];
echo "
";}
else {
echo "sql查询失败";}
echo "
";
}
?>