PHP中无法从数据库获取数据问题求助(附相关代码)
Hey there, let's figure out why you're not pulling data from your database. I spotted a couple of critical issues in your code that are almost certainly causing the problem, plus some fixes to make your code safer and more reliable.
Key Problems in Your Current Code
1. Missing Quotes Around String Values
If department and class are string-type columns (like storing names such as "Computer Science" or "12A"), your SQL query is invalid because you're not wrapping the values in single quotes. The database will interpret these values as column names or invalid identifiers instead of the actual data you're trying to match.
Your original problematic line:
$sql = "SELECT `student_id` , `name`, `htno`, `department`, `class` , `image_name` FROM student_detail where department=$department && class=$class";
Even if you added quotes, this approach carries major security risks (more on that next).
2. Severe SQL Injection Vulnerability
Directly inserting user-submitted $_POST values into your SQL query is a huge security risk. Attackers can manipulate these values to delete tables, steal sensitive data, or take over your database. You must use prepared statements to handle user input safely.
3. Unverified Connection & Inputs
- You don't check if your database connection
$connis actually valid. If the connection failed silently, your query will never run. - You assume
$_POST['department']and$_POST['class']always exist—if the form is submitted without these fields, your code will throw warnings and break.
Fixed & Secure Code
Here's a revised version of your code using prepared statements (the industry standard for safe database queries) with added checks:
<?php if(isset($_POST['search'])) { // First, confirm your database connection is working if (!$conn) { die("Connection failed: " . mysqli_connect_error()); } // Safely retrieve POST values (fallback to empty string if missing) $department = isset($_POST['department']) ? trim($_POST['department']) : ''; $class = isset($_POST['class']) ? trim($_POST['class']) : ''; // Use a prepared statement with placeholders (?) instead of direct variables $sql = "SELECT `student_id`, `name`, `htno`, `department`, `class`, `image_name` FROM student_detail WHERE department = ? AND class = ?"; // Prepare the statement $stmt = mysqli_prepare($conn, $sql); if (!$stmt) { die('Prepare Error: ' . mysqli_error($conn)); } // Bind parameters: "ss" means both are string types. Use "ii" if they're integers. mysqli_stmt_bind_param($stmt, "ss", $department, $class); // Execute the query mysqli_stmt_execute($stmt); // Get the result set $result = mysqli_stmt_get_result($stmt); if (!$result) { die('Execute Error: ' . mysqli_error($conn)); } $i = 1; while ($row = mysqli_fetch_array($result)) { ?> <tr> <td><?php echo $i++; ?></td> <td><?php echo htmlspecialchars($row['name']); ?></td> <td><?php echo htmlspecialchars($row['htno']); ?></td> <td><?php echo htmlspecialchars($row['department']); ?></td> <td><?php echo htmlspecialchars($row['class']); ?></td> <td> <!-- Sanitize image name to prevent XSS and path traversal --> <img src="your-image-directory/<?php echo htmlspecialchars($row['image_name']); ?>" alt="<?php echo htmlspecialchars($row['name']); ?>'s photo"> </td> </tr> <?php } // Clean up resources mysqli_stmt_close($stmt); } ?>
Additional Troubleshooting Steps
If you still don't get data after fixing the code:
- Verify data exists: Run a manual query in your database client (like phpMyAdmin) using hardcoded values, e.g.:
If this returns no rows, the issue is missing data, not your code.SELECT * FROM student_detail WHERE department='Computer Science' AND class='12A'; - Check column names: Ensure
student_id,image_name, etc., match exactly with your database table (case sensitivity depends on your database setup). - Debug POST data: Add
var_dump($_POST);at the top of your script to confirm thedepartmentandclassvalues are being submitted correctly.
内容的提问来源于stack exchange,提问作者Rahul Kumar Sharma

