2011-11-07 29 views


define ("MAX_SIZE","10000"); 

    //This function reads the extension of the file. It is used to determine if the file is an image by checking the extension. 
    function getExtension($str) { 
     $i = strrpos($str,"."); 
     if (!$i) { 
      return ""; 
     $l = strlen($str) - $i; 
     $ext = substr($str,$i+1,$l); 
     return $ext; 

    //This variable is used as a flag. The value is initialized with 0 (meaning no error found) and it will be changed to 1 if an errro occures. If the error occures the file will not be uploaded. 
    $errors = 0; 

    //Checks if the form has been submitted 
    if (isset($_POST['Submit'])) 
     //Reads the name of the file the user submitted for uploading 

     //If it is not empty 
     if ($image) 
      //Get the original name of the file from the clients machine 
      $filename = stripslashes($_FILES['image']['name']); 

      //Get the extension of the file in a lower case format 
      $extension = getExtension($filename); 
      $extension = strtolower($extension); 

      //If it is not a known extension, we will suppose it is an error and will not upload the file, otherwize we will do more tests 
      if (($extension != "jpg") && 
       ($extension != "jpeg") && 
       ($extension != "png") && 
       ($extension != "gif")) 
       //Print error message 
       echo '<h1>Unknown extension!</h1>'; 
      //Get the size of the image in bytes 
      //$_FILES['image']['tmp_name'] is the temporary filename of the file in which the uploaded file was stored on the server 

      //Compare the size with the maxim size we defined and print error if bigger 
      if ($size > MAX_SIZE*111111111111024) 
       echo '<h1>You have exceeded the size limit!</h1>'; 

      //We will give an unique name, for example the time in Unix time format 

      //The new name will be containing the full path where will be stored (images folder). 
      $imagepath='C:\\xampp\\htdocs\\biddingsystem\\Images\\' . $image_name; 

      //We verify if the image has been uploaded, and print an error instead 
      $copied = copy($_FILES['image']['tmp_name'], $imagepath); 
      if (!$copied) 
       echo '<h1>Picture upload failed!</h1>'; 

//If no errors registred, print the success message 
if(isset($_POST['Submit']) && !$errors && isset($_POST['image'])) 
    echo "<h1>Picture Uploaded Successfully! Try again!</h1>"; 


mysql_query("INSERT INTO items 
    (username, item, price, description, start_date, start_time, imagepath) 
    VALUES ('$username', '$_POST[item]', '$_POST[price]', '$_POST[description]','$_POST[start_date]', '$_POST[start_time]', '$imagepath') ") 
    or die ("Error - Couldn't add item"); 

    echo "Item added successfully"; 
    echo "<h1>You have added the following item:</h1>"; 
    $sql = "SELECT item, price, description, start_time, start_date, imagepath FROM items WHERE username = '$username' AND item='$_POST[item]'"; 
    $result = mysql_query($sql); 

$row = mysql_fetch_assoc($result); 
echo"<table border=2> 

      <td>Price</td><td>Description</td><td>Start time</td><td>Start date</td><td>Picture</td></tr> 

     <tr><td> $row[item]</td> 
       <td> $row[price]</td> 
       <td> $row[description]</td> 
      <td> $row[start_time]</td> 
      <td> $row[start_date]</td> 
      <td> $row[imagepath]</td> 

我试过使用<img src="<?php $imagepath ?>">来显示图像,但无济于事。我甚至尝试使用BLOB类型将实际图像本身存储在数据库中。然而,结果是一个充满奇怪字符的页面。我该如何解决这个问题?



你在混淆文件系统路径和web URL。您只需要存储/biddingsystem/Images/部分或甚至只显示名称并在显示时间动态生成完整路径。

另请注意,您没有正确格式化数据,这会导致一些错误和安全漏洞。我在前面的答案中解释了格式化规则,以Stack Overflow问题How to include a PHP variable inside a MySQL insert statement


已将其更改为相对路径,并且以下警告显示: 警告:copy(/biddingsystem/Images/1320662886.jpg)[function.copy]:未能打开流:C:\中没有此文件或目录。 xampp \ htdocs \ biddingsystem \ auction.php在线87 – user1033038


顺便说一句,我已经改变了这一行:$ imageData ='/ biddingsystem/Images /'.$ image_name; – user1033038


$ copied = copy($ _ FILES ['image'] ['tmp_name'],$ imageData); << --- line87 – user1033038


如果您想要使用第一种解决方案,请从路径中进行显示,请确保您指向的是可访问路径中的图像。从您列出的代码中,它看起来像$ imagepath是一个file://路径。在Web服务器上,您必须将其映射到相对的Web路径。



不需要第二次解决方案。 –


谢谢,我想我会坚持第一个解决方案。 – user1033038