<?php
$con=mysql_connect("localhost","username","password");
if($con==FALSE)
{
die('<html><body onload="alert(' . "'" . mysql_error() . "'" . ')"></body></html>');
}
mysql_select_db("management",$con);
echo mysql_error();
$s=mysql_query("SELECT `_Password` FROM `persons` WHERE `_Name`=" . '"' . $_POST["username"] . '"');
$row = mysql_fetch_array($s);
if(count($row)==0)
{echo '<html><body onload="alert( \'查无此人\')"></body></html>';}
else
{
echo $row['_Password'];
}
mysql_close($con);
?>
直接echo $sql;
输出的是Resouces Id #4
$con=mysql_connect("localhost","username","password");
if($con==FALSE)
{
die('<html><body onload="alert(' . "'" . mysql_error() . "'" . ')"></body></html>');
}
mysql_select_db("management",$con);
echo mysql_error();
$s=mysql_query("SELECT `_Password` FROM `persons` WHERE `_Name`=" . '"' . $_POST["username"] . '"');
$row = mysql_fetch_array($s);
if(count($row)==0)
{echo '<html><body onload="alert( \'查无此人\')"></body></html>';}
else
{
echo $row['_Password'];
}
mysql_close($con);
?>
直接echo $sql;
输出的是Resouces Id #4
![](http://g.hiphotos.bdimg.com/album/s%3D550%3Bq%3D90%3Bc%3Dxiangce%2C100%2C100/sign=788f22e2adaf2eddd0f149ecbd2b70d4/4a36acaf2edda3cc725fe4c400e93901203f929e.jpg?v=tbs)