Use a prepared statement when values come from a request or another variable source. Escape database values when placing them into HTML.
<?php
mysqli_report(MYSQLI_REPORT_ERROR | MYSQLI_REPORT_STRICT);
$connection = new mysqli('localhost', 'db_user', 'db_password', 'database_name');
$connection->set_charset('utf8mb4');
$class = 'Four';
$stmt = $connection->prepare('SELECT id, name, class, mark FROM student WHERE class = ? ORDER BY id');
$stmt->bind_param('s', $class);
$stmt->execute();
$result = $stmt->get_result();
while ($row = $result->fetch_assoc()) {
echo htmlspecialchars($row['name'], ENT_QUOTES, 'UTF-8') . ' - ';
echo htmlspecialchars($row['class'], ENT_QUOTES, 'UTF-8') . '
';
}
?>
| id | name | class | mark |
|---|---|---|---|
| 1 | John Deo | Four | 75 |
| 2 | Max Ruin | Three | 85 |
| 3 | Arnold | Three | 55 |
| 4 | Krish Star | Four | 60 |
| 5 | John Mike | Four | 60 |
| 6 | Alex John | Four | 55 |
| 7 | My John Rob | Fifth | 78 |
<?Php
require "config.php";// Database connection file.
$query="select * from student LIMIT 0,5 ";
//Variable $connection is declared inside config.php file & used here
if ($result_set = $connection->query($query)) {
while($row = $result_set->fetch_array(MYSQLI_ASSOC)){
echo $row['id'],$row['name'],$row['class'],$row['mark']."<br>";
}
$result_set->close();
}
?>
More about the above code is here.
| $connection | Connection object Declared inside config.php file |
| $result_set | query() returns True of False based on success or failure of Query. On success it returns mysqli_result object. |
| fetch_array | Returns row of data from result set as array of string. NULL is returned if no more row is available to return. |
| id | name | class | mark | sex |
|---|---|---|---|---|
| 1 | John Deo | Four | 75 | female |
| 2 | Max Ruin | Three | 85 | male |
| 3 | Arnold | Three | 55 | male |
| 4 | Krish Star | Four | 60 | female |
| 5 | John Mike | Four | 60 | female |
<?Php
require "config.php";// Database connection file.
$query="select * from student LIMIT 0,5 ";
if ($result_set = mysqli_query($connection,$query)) {
while($row = $result_set->fetch_array(MYSQLI_ASSOC)){
echo $row['id'],$row['name'],$row['class'],$row['mark']."<br>";
}
$result_set->close();
}
?>
<?Php
require "config.php";// Database connection
if($stmt = $connection->query("SELECT id, name ,class, mark FROM student")){
echo "No of records : ".$stmt->num_rows."<br>";
while ($row = $stmt->fetch_assoc()) {
echo $row['id'],$row['name'],$row['class'].$row['mark']."<br>";
}
}else{
echo $connection->error;
}
?>
require "config.php"; // Database Connection
////////////////
/////// Display records /////
$sql="SELECT id,name,class,mark FROM student LIMIT 0,5 ";
echo "<table>
<tr><th>id</th><th>Name</th><th>Class</th><th>Mark</th></tr>";
foreach ($dbo->query($sql) as $row) {
echo "<tr ><td>$row[id]</td><td>$row[name]</td><td>$row[class]</td><td>$row[mark]</td></tr>";
}
echo "</table>";
MySQLi select query to get data

$query="select * from student WHERE class='Four'";
SQL WHERE Condition
Author & Instructor at plus2net
I write and maintain practical tutorials on Python, PHP, SQL, JavaScript, HTML, jQuery, and web development at plus2net. The tutorials focus on clear explanations, working examples, and code that readers can test and adapt while learning.
| mariel | 16-02-2012 |
| thank you...it works.. | |
| Simon | 22-02-2012 |
| Thanks dude, this tutorial helped me a lot. | |
| Atar | 25-05-2012 |
| Hi can you tell me how to insert date month and year combine in databese | |
| Venedict Francisco | 07-09-2013 |
| how can i post or display data information from the two different table? | |
| smo1234 | 09-06-2015 |
| You can always combine more than one table and display information. You can select multiple tables in a select statement and join more than two tables by using LEFT join Check SQL section for more details. | |