connect_errno) { echo "db connection error : " . $mysql->connect_error; exit(); } $sql = "SELECT * FROM movieView WHERE 1=1 " . " AND title LIKE '%" . $_REQUEST['title'] . "%'"; if($_REQUEST['rating'] != "ALL" ) { $sql .= " AND rating ='" . $_REQUEST["rating"] . "'"; } if($_REQUEST['genre'] != "ALL" ) { $sql .= " AND genre = '" . $_REQUEST["genre"] . "'"; } $sql .= " ORDER BY " . $_REQUEST['sortorder']; $results = $mysql->query($sql); // echo "