query($sql) or die(printf("Error: %s ".$sql, $mysqli->sqlstate)); $result = $mysqli->query($sql); $nav_body=""; while($row = $result->fetch_assoc()) { #過濾撈出資料 $row['sn'] = intval($row['sn']); //http://www.w3school.com.cn/php/func_string_htmlspecialchars.asp $row['title'] = htmlspecialchars($row['title'], ENT_QUOTES); // 轉換雙引號和單引號 $row['url'] = htmlspecialchars($row['url'], ENT_QUOTES); // 轉換雙引號和單引號 $row['target'] = $row['target'] ? " target='_blank'":""; $nav_body .= "