SQL- , "", . , PHP script, - :
<?php
$smth_value = $_POST["smth"];
$smth_user = $_POST["user"];
$smth_email = $_POST["email"];
$sql1 = "SELECT * FROM table_name WHERE smth = '".$smth_value."'";
$sql2 = "UPDATE table_name SET smth ='".$smth_email."' WHERE user = '".$smth_user."'";
mysql_query($sql1);
mysql_query($sql2);
?>
( - ), "" SQL , SQL , SQL , . , - "smth" - :
';DELETE FROM table_name WHERE 1=1 OR smth='
$sql1 :
SELECT * FROM table_name WHERE smth = '';DELETE FROM table_name WHERE 1=1 OR smth=''
... table_name.
PHP, mysql_escape_string, . , , . , . , .