P H P - SQLi - Contact




<?php
    $server = 'localhost';{
      $user = 'root';
      $password = '';
      $database = 'php';
      $contact = @mysqli_connect($server, $user, $password);
         if ($contact)
             mysqli_select_db ($contact, $database);
             echo 'error: ' . mysql_error($contact);
             } else {
               if (isset($_POST['firstname'])) {
         $sql = "
             INSERT INTO
             friends(firstname, lastname)
             VALUES ('{$_POST['firstname']}', '{['lastname']}')
             ";
         $query = mysqli_query ($contact, $sql);
             echo 'SQL: ' . $sql; {
             $sql = "SELECT * FROM friends ORDER BY lastname";
             $query = mysqli_query ($contact, $sql);
             echo '<h1>You have ' . mysqli_num_rows ($query) . ' friends</h1>';
             echo '<ul>';
                  while ($friend = mysqli_fetch_assoc($query)) {
                  echo "<li>{$friend['firstname']} {$friend['lastname']}
                  }
         echo '<ul>';
         mysqli_free_result($query);
         echo 'Could not connect to the database to build'
         . mysqli_connect_error($contact);
         }
?>


  b a c k