" $dbpass = "" $dbname = "" # open a link to the db, the filehandle is $link $link = mysqli_connect($dbhost, $dbuser, $dbpass, $dbname); # if connection fails, let us know if(mysqli_connect_errno()) { print("DB fail: " . mysqli_connect_error()); exit(); } # we don't need no sql injection... $x = mysqli_real_escape_string($link, $_POST[x]); # create an SQL query $query = "SELECT * FROM "; # execute the query $result = mysqli_query($link, $query); # if the query failed, let us know if(mysqli_errno($link)) { print("Query fail: " . mysqli_error()); exit(); } # free up the result after we're done with it mysqli_free_result($result); # close the filehandle to the db mysqli_close($link); # # HTML # print("\n"); print("\n"); print(" \n"); print(" \n"); print(" title\n"); print(" \n"); print(" \n"); print(" \n"); print(" \n"); print("

\n"); print(" text text
\n"); print(" text text\n"); print("

\n"); print("\n"); print(" \n"); print("
\n"); print(" \n"); print(" \n"); print(" \n"); print(" \n"); print(" \n"); print(" \n"); print(" \n"); print(" \n"); print(" \n"); print(" \n"); print(" \n"); print(" \n"); print(" \n"); print(" \n"); print(" \n"); print(" \n"); print("
ab
12
34
\n"); print(" \n"); print("\n"); ?>