高手进来看看这个mysql怎么注入
代码在这里了:
link_data();
$query1="select choice from title where id=".$HTTP_GET_VARS["id"]."";
$result1=mysql_query($query1);
$row1=mysql_fetch_array($result1);
$my=$HTTP_POST_VARS["choice"];
if ($row1["choice"]=="a")
{
$query="update choice set num=num+1 where id=".$my;
$result=mysql_query($query);
session_register("votes");
echo "<script language='javascript'>alert('投票成功!');window.close();</script>";
}
elseif ($row1["choice"]=="b")
{
for ($i=0;$i<count($my);$i++)
{
$query="update choice set num=num+1 where id=".$my[$i];
$result=mysql_query($query);
session_register("votes");
}
echo "<script language='javascript'>alert('投票成功!');history.go(-1);</script>";
}
我要构造怎样的url来搞定他