Note that there are some explanatory texts on larger screens.

plurals
  1. PO
    primarykey
    data
    text
    <p>First: use <code>$_GET['voted']</code> instead of <code>$_submit['voted']</code>.</p> <p>In addition the links you built are wrong. Change </p> <pre><code> Echo "&lt;a href='index.php?site=kumu'?mode=vote&amp;voted=1&amp;id=".$ratings['id']."&gt;1&lt;/a&gt; | "; //The HREF was ".$_SERVER['PHP_SELF']." before Echo "&lt;a href='index.php?site=kumu'?mode=vote&amp;voted=2&amp;id=".$ratings['id']."&gt;2&lt;/a&gt; | "; Echo "&lt;a href='index.php?site=kumu'?mode=vote&amp;voted=3&amp;id=".$ratings['id']."&gt;3&lt;/a&gt; | "; Echo "&lt;a href='index.php?site=kumu'?mode=vote&amp;voted=4&amp;id=".$ratings['id']."&gt;4&lt;/a&gt; | "; Echo "&lt;a href='index.php?site=kumu'?mode=vote&amp;voted=5&amp;id=".$ratings['id']."&gt;5&lt;/a&gt;&lt;p&gt;"; </code></pre> <p>to</p> <pre><code> Echo "&lt;a href=index.php?site=kumu&amp;mode=vote&amp;voted=1&amp;id=".$ratings['id']."&gt;1&lt;/a&gt; | "; //The HREF was ".$_SERVER['PHP_SELF']." before Echo "&lt;a href=index.php?site=kumu&amp;mode=vote&amp;voted=2&amp;id=".$ratings['id']."&gt;2&lt;/a&gt; | "; Echo "&lt;a href=index.php?site=kumu&amp;mode=vote&amp;voted=3&amp;id=".$ratings['id']."&gt;3&lt;/a&gt; | "; Echo "&lt;a href=index.php?site=kumu&amp;mode=vote&amp;voted=4&amp;id=".$ratings['id']."&gt;4&lt;/a&gt; | "; Echo "&lt;a href=index.php?site=kumu&amp;mode=vote&amp;voted=5&amp;id=".$ratings['id']."&gt;5&lt;/a&gt;&lt;p&gt;"; </code></pre> <p><strong>UPDATE</strong></p> <p>Replace the statement:</p> <pre><code> if(isset($_submit['voted'])) { mysql_query ("UPDATE vote SET total= total+$voted, votes = votes+1 WHERE id = $id"); Echo "Your vote has been cast &lt;p&gt;"; } </code></pre> <p>With:</p> <pre><code> if(isset($_GET['voted']) &amp;&amp; is_numeric($_GET['voted'])) { mysql_query ("UPDATE vote SET total= total+ " . $_GET['voted'] . ", votes = votes+1 WHERE id = " . $_GET['id']); Echo "Your vote has been cast &lt;p&gt;"; } </code></pre> <p>Of course, a better parameter validation and escaping is mandatory in order to prevent any SQLInjection.</p>
    singulars
    1. This table or related slice is empty.
    plurals
    1. This table or related slice is empty.
    1. This table or related slice is empty.
    1. This table or related slice is empty.
    1. This table or related slice is empty.
    1. This table or related slice is empty.
 

Querying!

 
Guidance

SQuiL has stopped working due to an internal error.

If you are curious you may find further information in the browser console, which is accessible through the devtools (F12).

Reload