Advertisement
Guest User

Untitled

a guest
Apr 3rd, 2017
85
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.78 KB | None | 0 0
  1. var mysql = require('mysql');
  2. var express = require('express');
  3. var connection = mysql.createConnection({
  4. host: 'localhost',
  5. user: 'root',
  6. database: 'injection',
  7. password: '',
  8. multipleStatements: true // Mengaktifkan eksekusi multiple statement
  9. });
  10. connection.connect(function(err){
  11. if(!err) {
  12. console.log("Berhasil terkoneksi dengan database !!!");
  13. } else {
  14. console.log("Gagal terkoneksi dengan database !!!");
  15. }
  16. });
  17. var app = express();
  18. app.get('/:id', function(req, res, next) {
  19. //Query SQL yang tidak terfilter dengan benar
  20. connection.query('SELECT * FROM users WHERE id="' + req.param('id') + '"', function(err, rows, fields) {
  21. if (err) {
  22. next(err);
  23. return;
  24. }
  25. res.send(JSON.stringify(rows));
  26. });
  27. });
  28. app.listen(3000);
  29. console.log('Server Berjalan Port 3000 :)');
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement