$strSQL = "SELECT * FROM Parent WHERE (parent_no LIKE '%".$_GET["txtKeyword"]."%' or parent_name LIKE '%".$_GET["txtKeyword"]."%' or parent_ID LIKE '%".$_GET["txtKeyword"]."%')";
แก้เป็น
$_GET['txtKeyword'] = mysql_real_escape_string($_GET['txtKeyword']);
$strSQL = "SELECT * FROM Parent WHERE (parent_no LIKE '%{$_GET['txtKeyword']}%' or parent_name LIKE '%{$_GET['txtKeyword']}%' or parent_ID LIKE '%{$_GET['txtKeyword']}%')";