//get id from url //$man_id = $_GET['model']; $man_name=$_GET['man']; $error = ''; //$man_id='15'; if (preg_match("/([%\$#\*\=.\\\\(\)\?]+)/", $man_name)) { $error .= 'This has a special character'; $man_name = ''; } include ("includes/sanitizefxn.php"); stripslashes(sanitize($man_name)); // connect to db include_once ("includes/connectdb.php"); //connect to table $sql="SELECT printer_model.model_id, printer_make.make_name, printer_model.model_name, printer_pass.user_value, printer_pass.pass_value FROM printer_model JOIN printer_make ON printer_make.make_id = printer_model.make_id JOIN printer_pass ON printer_pass.model_id = printer_model.model_id WHERE printer_make.make_name='$man_name'"; $result=mysqli_query($c,$sql) or die(mysql_error()); if (mysqli_num_rows($result) < 1) { //there are none, so say so $display_block = "
We do not have any listings for this manufacturer.
"; } else { //create the display string $display_block = "| Make | Model | Username | Password | 
|---|---|---|---|
| $man_name | $modelname | $user | $pass | 
| include_once ("includes/header.inc.php");
?> List of echo $man_name;?> Printer Passwordsecho $display_block; ?> include_once ("includes/footer.inc.php"); ?> |