0

Hi I am trying to insert 6 values into a table named post, but it wont work and I get an error. Where is the mistake in my php code?

Error:

Parse error: syntax error, unexpected '"', expecting identifier (T_STRING) or variable (T_VARIABLE) or number (T_NUM_STRING) in C:\xampp\htdocs\next.php on line 22

    <?php
    $cookie_name = 'longitude';
    //check if cookies available
    if(!isset($_Post["submit"])) {
      print 'error';
    } else {

if (
            empty($_POST['title']),
            empty($_POST['text'])

        ) {
            $message['error'] = 'Es wurden nicht alle Felder ausgefüllt.';
        } 
      $id = 'userid';
      $_COOKIE["$id"];
      $longitude = 'longitude';
      $_COOKIE["$longitude"];
      $latitude = 'latitude';
      $_COOKIE["$latitude"];
       $date = date('Y-m-d H:i:s');
            $mysqli = @new mysqli('localhost', 'root', '', 'local');
                if ($mysqli->connect_error) {
                    $message['error'] = 'Datenbankverbindung fehlgeschlagen: ' . $mysqli->connect_error;
                }
                $query = sprintf(
                    "INSERT INTO post (autorid, date, longitude, latitude, title, text)
                    SELECT * FROM (SELECT '%s') as new_post
                    WHERE NOT EXISTS (
                        SELECT autorid FROM post WHERE autorid = '$_COOKIE["$id"]' // line22
                    ) LIMIT 1;",
                    $mysqli->real_escape_string(@$_POST[$_COOKIE["$id"]]),
                    $mysqli->real_escape_string($_POST['$date']),           
                    $mysqli->real_escape_string($_POST['title']),
                    $mysqli->real_escape_string($_POST['text']),
                    $mysqli->real_escape_string(@$_POST[$_COOKIE["$longitude"]]),
                    $mysqli->real_escape_string(@$_POST[$_COOKIE["$latitude"]]),
                    $mysqli->real_escape_string(@$_POST[$_COOKIE["$id"]])

                );


                $mysqli->query($query);
                if ($mysqli->affected_rows == 1) {

                    header('Location: http://' . $_SERVER['HTTP_HOST'] . '/loc/main.php');

                } else {

                }

                $mysqli->close();
            }

    ?>
    <html>
    <head>
        <meta charset="UTF-8" /> 
        <title>
            HTML Document Structure
        </title>
        <link rel="stylesheet" type="text/css" href="style.css" />

        <link rel="stylesheet" href="http://code.jquery.com/mobile/1.3.0/jquery.mobile-1.3.0.min.css" />
        <script src="http://code.jquery.com/jquery-1.8.2.min.js"></script>
        <script src="http://code.jquery.com/mobile/1.3.0/jquery.mobile-1.3.0.min.js"></script>

        <!-- Einstellungen zur Defintion als WebApp -->
        <meta name="apple-mobile-web-app-capable" content="yes" />
        <meta name="viewport" content="width=device-width, initial-scale=1, maximum-scale=1">

    </head>
    <body>



    <div id="wrapper1" data-role="fieldcontain">
        <form name="login-form" class="login-form" action="./next.php" method="post">

            <div class="header">
            </div>

            <div class="content">
            <label for="username"></label>
            <input name="title" type="text" class="input title" placeholder="title" id="title"/>
            <input name="text" type="text" class="input text" placeholder="text" id="text"/>        
            </div>

            <div class="footer">
            <input type="submit" name="submit" value="Login" class="button" data-theme="b"/>
            </div>

        </form>


    <div class="gradient"></div>


    </body>
    </html>
brabus85
  • 71
  • 7
  • Why are you doing: `$id = 'userid';` `$_COOKIE["$id"];` and not only `$_COOKIE['userid']`? – venca Jun 10 '15 at 07:18

3 Answers3

2

You have to use double quotes arrount the variable $_COOKIE["$id"] and concat the string:

SELECT autorid FROM post WHERE autorid = '".$_COOKIE["$id"]."'

But better is to use prepared statements.

Jens
  • 67,715
  • 15
  • 98
  • 113
1
  SELECT autorid FROM post WHERE autorid = '$_COOKIE["$id"]'

to

  SELECT autorid FROM post WHERE autorid = ".$_COOKIE["$id"]."

still not safe as far as sql injection is concerned.

Danyal Sandeelo
  • 12,196
  • 10
  • 47
  • 78
0

The quotes $_COOKIE["$id"] => $_COOKIE[$id]

venca
  • 1,196
  • 5
  • 18