Guest User

Untitled

a guest
Jan 18th, 2019
115
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.84 KB | None | 0 0
  1. var user = req.body;
  2. var imgurl=projectDir +"/uploads/"+req.files.displayImage.name;
  3. var sql= "INSERT INTO users values('','"+user.name+"','"+user.email+"','"+user.user+"','"+user.pass+"','"+imgurl+"',now())";
  4.  
  5. D:
  6. ode/uploads/canvas.png
  7.  
  8. function mysql_real_escape_string (str) {
  9. return str.replace(/[x08x09x1anr"'\%]/g, function (char) {
  10. switch (char) {
  11. case "":
  12. return "\0";
  13. case "x08":
  14. return "\b";
  15. case "x09":
  16. return "\t";
  17. case "x1a":
  18. return "\z";
  19. case "n":
  20. return "\n";
  21. case "r":
  22. return "\r";
  23. case """:
  24. case "'":
  25. case "\":
  26. case "%":
  27. return "\"+char; // prepends a backslash to backslash, percent,
  28. // and double/single quotes
  29. }
  30. });
  31. }
  32.  
  33. var sql= "INSERT INTO users values('','"+user.name+"','"+user.email+"','"+user.user+"','"+user.pass+"','"+mysql_real_escape_string(imgurl)+"',now())";
  34.  
  35. var sql= "INSERT INTO users SET ?";
  36. // Connection attained as listed above.
  37. connection.query( sql, { name:user.name, email:user.email, user:user.user, pass:user.pass, image:imgurl, timestamp:now()}, function(err, result){
  38. // check result if err is undefined.
  39. });
  40.  
  41. var mysql = require('mysql');
  42. var connection = mysql.createConnection(...);
  43. var userId = 'some user provided value';
  44. var sql = 'SELECT * FROM users WHERE id = ' + connection.escape(userId);
  45. connection.query(sql, function(err, results) {
  46. // ...
  47. });
  48.  
  49. var mysql = require('mysql');
  50. var connection = mysql.createConnection(...);
  51. var userId = 'some user provided value';
  52. var sql = 'SELECT * FROM users WHERE id = ' + mysql.escape(userId);
  53. connection.query(sql, function(err, results) {
  54. // ...
  55. });
Add Comment
Please, Sign In to add comment