如何sql更新两个条件

I have a problem with the condition 'where'.
I want one more condition in this code:

$sql="UPDATE
            coursegrade
        SET 

            FirstExam='" . mysql_real_escape_string($_POST['FirstExam']) . "',
            SecondExam='" . mysql_real_escape_string($_POST['SecondExam']) . "',
            ThirdExam='" . mysql_real_escape_string($_POST['ThirdExam']) . "',
            Assignments='" . mysql_real_escape_string($_POST['Assignments']) . "',
            FinalExam='" . mysql_real_escape_string($_POST['FinalExam']) . "'
        WHERE 
            SID=" . mysql_real_escape_string($_POST['SID'])  ;

Tell now I have no problem .. but the problem is that I don't know how to set the second condition.

CourseID=" . mysql_real_escape_string($_POST['CourseID'])

I want the condition to be something like...

WHERE
SID=" . mysql_real_escape_string($_POST['SID']) 
AND CourseID=" . mysql_real_escape_string($_POST['CourseID'])

How could I do it?

Unless you use heredoc syntax php will parse strings on a single line.

ie the rendered clause is:

"WHERE SID=19AND CourseID=45"

Basically you missed a space before

"AND CourseID=" . mysql_real_escape_string($_POST['CourseID'])

or you could put quotes around the values

"SID='" . mysql_real_escape_string($_POST['SID']) . "'
AND CourseID='" . mysql_real_escape_string($_POST['CourseID'])."'"

This is may help

WHERE
SID=" . mysql_real_escape_string($_POST['SID']) 
OR CourseID=" . mysql_real_escape_string($_POST['CourseID'])

or

WHERE
SID in (
  mysql_real_escape_string($_POST['SID']),
  mysql_real_escape_string($_POST['CourseID'])
)

its will work for INT value of SID and CourseID

You can try this, and let me know if there is error message

$sql="UPDATE coursegrade
SET 
        FirstExam = '" . mysql_real_escape_string($_POST[' FirstExam ']) . "',
        SecondExam = '" . mysql_real_escape_string($_POST[' SecondExam ']) . "',
        ThirdExam = '" . mysql_real_escape_string($_POST[' ThirdExam ']) . "',
        Assignments = '" . mysql_real_escape_string($_POST[' Assignments ']) . "',
        FinalExam = '" . mysql_real_escape_string($_POST[' FinalExam ']) . "'
WHERE
        SID = ". mysql_real_escape_string($_POST['SID'])."
AND
        CourseID = " . mysql_real_escape_string($_POST['CourseID']) .";