Variables from query string
$FirstName = $_GET['firstname'];
$LastName = $_GET['lastname'];
$NewFirstName = $_GET['newfirstname'];
Escape the variables
if (!(get_magic_quotes_gpc())) {
$FirstName = addslashes($FirstName);
$LastName = addslashes($LastName);
$NewFirstName = addslashes($NewFirstName);
}
Connect to database
$db_addr = "localhost";
$db_user = "username";
$db_pass = "password";
$db_name = "database";
$db_table = "users";
$connect = mysql_connect($db_addr,$db_user,$db_pass);
if (!($connect)) {
echo "There was a problem.";
exit();
}
if (!(mysql_select_db($db_name))) {
echo "There was a problem.";
exit();
}
Create a table
$make_table = "create table $db_table (first_name varchar(50) not null, last_name varchar(50) not null)";
if (mysql_query($make_table)) {
$message = "Table Created";
}
else {
$message = "There was a problem.";
}
Add a record
if (mysql_query("insert into $db_table values ('$FirstName', '$LastName')")) {
$message = "User Created";
}
else {
$message = "There was a problem.";
}
Change a record
if (mysql_query("update $db_table set first_name = '$NewFirstName' where last_name = '$LastName'")) {
$message = "User Edited";
}
else {
$message = "There was a problem.";
}
Delete a record
if (mysql_query("delete from $db_table where last_name = '$LastName'")) {
$message = "User Deleted";
}
else {
$message = "There was a problem.";
}
Display a record
$user_query = mysql_query("select * from $db_table");
while ($user_data = mysql_fetch_array($user_query)) {
echo $user_data["first_name"] . " " . $user_data["last_name"] . "<br>";
}