Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- $member_id = $formdata['update'];
- $surname = $formdata['surname'];
- $other_name = $formdata['othername'];
- $contactmethod = $formdata['contactmethod'];
- $email = $formdata['email'];
- $mobilenum = $formdata['mobilenum'];
- $phonenum = $formdata['phonenum'];
- $occupation = $formdata['occupation'];
- $userpass = $formdata['userpass'];
- if(!isset($formdata['magazine']))
- $magazine = 0;
- else
- $magazine = 1;
- //Get ready to talk to the DB
- $db = getDBConnection();
- //Make a prepared query so that we can use data binding and avoid SQL injections.
- $insertUser = $db->prepare('INSERT into member VALUES
- (:surname, :other_name, :contact_method,
- :email, :mobile, :landline, :magazine, :street,
- :suburb, :postcode, :password,
- :occupation) WHERE member_id=$member_id');
- //Bind the data from the form to the query variables.
- //Doing it this way means PDO sanitises the input which prevents SQL injection.
- $insertUser->bindParam(':surname', $surname, PDO::PARAM_STR);
- $insertUser->bindParam(':other_name', $other_name, PDO::PARAM_STR);
- $insertUser->bindParam(':contact_method', $contactmethod, PDO::PARAM_STR);
- $insertUser->bindParam(':email', $email, PDO::PARAM_STR);
- $insertUser->bindParam(':mobile', $mobilenum, PDO::PARAM_STR);
- $insertUser->bindParam(':landline', $phonenum, PDO::PARAM_STR);
- $insertUser->bindParam(':magazine', $magazine, PDO::PARAM_INT);
- $insertUser->bindParam(':street', $streetaddr, PDO::PARAM_STR);
- $insertUser->bindParam(':suburb', $suburbstate, PDO::PARAM_STR);
- $insertUser->bindParam(':postcode', $postcode, PDO::PARAM_INT);
- $insertUser->bindParam(':password', $userpass, PDO::PARAM_STR);
- $insertUser->bindParam(':occupation', $occupation, PDO::PARAM_STR);
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement