mysqli_stmt::bind_result(): Number of bind variables doesn't match number of fields in prepared statement

前端 未结 2 1672
隐瞒了意图╮
隐瞒了意图╮ 2020-12-11 09:35

I’ve been trying to code a login form in PHP using a prepared statement but every time I try to log in I get the following error:

mysqli_stmt::bind_re

2条回答
  •  春和景丽
    2020-12-11 10:00

    $mysqli->prepare("SELECT username, password FROM users WHERE username = ? AND password = ?");
    $username = $_POST['name'];
    $password = $_POST['password'];
    $stmt->bind_param('ss' ,$username ,$password);
    $stmt->execute();
    $stmt->bind_result($username ,$password);
    

    Your select syntax was wrong, the correct syntax is SELECT field1, field2, field3 FROM TABLE WHERE field1 = ? AND field2 = ?

    To select more fields simply seperate them by a comma and not an AND

    Also, I realize that you're saving your passwords in plaintext which is bad practice, consider hashing them using the numerous hashing functions out there like sha1()

提交回复
热议问题