时间:2021-07-01 10:21:17 帮助过:19人阅读
$dbhandle = mssql_connect($myServer, $myUser, $myPass) or die("连接不上数据库"); //select a database to work with$selected = mssql_select_db($myDB, $dbhandle) or die("连接不上指定数据库"); $username=trim($_POST['username']);$password=trim($_POST['pass']);//declare the SQL statement that will query the database$query = "select top 6 * from WEB_VIEW where DNBH='$username' order by SFMonth desc ";//execute the SQL query and return records$result = mssql_query($query) or die ("查询数据失败: ".mysql_error()); //连接数据库,用于输出查询结果$resultPass = mssql_query($query) or die ("查询数据失败: ".mysql_error()); //连接数据库,用于判断密码$numRows = mssql_num_rows($result); $numRowsPass = mssql_num_rows($resultPass); //$row=mssql_fetch_array($result);$rowPass=mssql_fetch_array($resultPass);session_start();$ask=$_POST['ask'];$dbpass=trim($rowPass[3]);$dbusername=trim($rowPass[0]);if ($username <> $dbusername || $password <> substr($dbpass,-4)) {echo "
你在select语句里这样写:
SUBSTRING(要截取的字段(密码),indexStart,indexEnd) jiequA, 要截取的字段(密码) A
jiequA用来判断就是了。