<?
if ($REQUEST_METHOD=="POST") {
# double-up apostrophes
$textfield = str_replace("'","''",$textfield);
$table = str_replace("'","''",$table);
$c = str_replace("'","''",$c);
$query = "SELECT * FROM $table WHERE $c LIKE '$textfield%'";
$result = mysql_query($query)
or die("Query failed");
/* fetch rows in reverse order */
for ($i = mysql_num_rows($result) - 1; $i >= 0; $i--) {
if (!mysql_data_seek($result, $i)) {
echo "Cannot seek to row $i\n";
continue;
}
if(!($row1 = mysql_fetch_object($result)))
continue;
echo "$row1->$c<br />\n";}
mysql_free_result($result); }
?>
<form name="form1" method="post" action="search1.php">
<select name="table">
<option value="name">name</option>
<option value="address">address</option>
<option value="hours">hours</option>
<option value="info">info</option>
</select>
table
<select name="c">
<option>NAME TABLE</option>
<option value="name_id">id</option>
<option value="namefirst">first name</option>
<option value="namelast">last name</option>
<option>ADDRESS TABLE</option>
<option value="address">address</option>
<option value="city">city</option>
<option value="state">state</option>
<option value="zip">zip</option>
<option> </option>
<option>HOURS TABLE</option>
<option> </option>
<option value="hours">hours worked</option>
</select>
coloumn
<input type="text" name="textfield">
<input type="submit" name="Submit" value="Submit">
</form>