Ok, I have this PHP $_POST['username'] variable and I need to query everything on the user via MYSQL. The only problem is it keeps throwing me errors.
something like
$user = $_POST['username'];
$query = mysql_query("SELECT * FROM user WHERE username = $user");
I've tried
$query = mysql_query("SELECT * FROM user WHERE username = `$user`");
$query = mysql_query("SELECT * FROM user WHERE username = ".$user);
Not sure what i'm doing wrong.
SQL injection. DO read aboutparameterized queries.