to all you masters out there can you please help a brother out!!
i have this code and everytime i run it i get this error
You have an error in your SQL syntax. Check the manual that corresponds to your MySQL server version for the right syntax to use near 'WHERE username = 'admin',' at line 1
can some help me please
<?php
if (isset($_POST['submit']) && $_POST['submit'] == "Update") {
$query_update = "UPDATE user SET " .
"first_name = '" . $_POST['first_name'] . "', " .
"last_name = '" . $_POST['last_name'] . "', " .
"address1 = '" . $_POST['address1'] . "', " .
"address2 = '" . $_POST['address2'] . "', " .
"city = '" . $_POST['city'] . "', " .
"postcode = '" . $_POST['postcode'] . "', " .
"' WHERE username = '" . $_SESSION['username'] . "', " ;
$result_update = mysql_query($query_update)
or die(mysql_error());
echo "query1: " . $query;
$query = "SELECT * FROM user " .
"WHERE username = '" . $_SESSION['username'] . "' " .
"AND password = (PASSWORD('" .
$_SESSION['password'] . "'))";
$result = mysql_query($query)
or die(mysql_error());
echo "query2: " . $query;
$row = mysql_fetch_array($result);
// $hobbies = explode(", ", $row['hobbies'])
?>