thinkphpÔõÑùɨ³ýÌØÊâ×Ö·û
1.ʹÓÃPHPÄÚÖú¯Êý
ÔÚPHPÖУ¬ÓÐÐí¶à×Ö·û´®²Ù×÷º¯Êý¿É¹©Ê¹Óã¬Èçstr_replace¡¢preg_replaceµÈ¡£ÎÒÃÇ¿ÉÒÔʹÓÃËüÃÇÀ´É¨³ýһЩ³£¼ûµÄÌØÊâ×Ö·û¡£ºÃ±È£¬ÎÒÃÇ¿ÉÒÔʹÓÃÒÔÏ´úÂëɨ³ýÓû§ÊäÈëµÄµ¥ÒýºÅºÍË«ÒýºÅ£º
$str = $_POST['input']; $str = str_replace(array("'", "\""), '', $str);
µÇ¼ºó¸´ÖÆ
ÔÚÒÔÉÏ´úÂëÖУ¬ÎÒÃÇÊ×ÏÈ»ñÈ¡ÁËÓû§Ìá½»µÄÊý¾Ý£¬È»ºóʹÓÃstr_replaceº¯Êý½«ÆäÖеĵ¥ÒýºÅºÍË«ÒýºÅÌ滻Ϊ¿Õ×Ö·û´®£¬´Ó¶øɨ³ýÁËÕâЩÌØÊâ×Ö·û¡£
²»¹ý£¬PHPº¯ÊýÓÐÐí¶àÏÞÖÆ£¬ÎÞ·¨º¸ÇËùÓÐÌØÊâ×Ö·û¡£Òò´Ë£¬ÎÒÃÇ¿ÉÒÔʹÓÃÕýÔò±í´ïʽµÄ·½·¨À´É¨³ýÌØÊâ×Ö·û¡£
Á¬Ã¦Ñ§Ï°¡°PHPÃâ·ÑѧϰÌõ¼Ç£¨ÉîÈ룩¡±£»
2.ʹÓÃÕýÔò±í´ïʽ
ÕýÔò±í´ïʽÊÇÒ»¸öÓÃÓÚÆ¥ÅäÎı¾×Ö·ûµÄ¹¤¾ß¡£Ê¹ÓÃpreg_replaceº¯ÊýºÍÕýÔò±í´ïʽ¿ÉÒÔÔÚPHPÖÐÏû³ýÌØÊâ×Ö·û¡£ÏêϸʵÏÖ´úÂëÈçÏ£º
$str = $_POST['input']; $str = preg_replace('/[\'\"\\\]/', '', $str);
µÇ¼ºó¸´ÖÆ
ÔÚÒÔÉÏ´úÂëÖУ¬ÎÒÃÇʹÓÃpreg_replaceº¯ÊýºÍÕýÔò±í´ïʽ£¬Æ¥ÅäÓû§ÊäÈëÖеĵ¥ÒýºÅ¡¢Ë«ÒýºÅºÍ·´Ð±¸Ü£¬´Ó¶ø½«ÆäÌæ»»³É¿Õ×Ö·û´®£¬Íê³ÉÌØÊâ×Ö·ûµÄɨ³ý¡£
³ýÁËÉÏÊöÒªÁ죬ÉÐÓÐһЩÆäËûµÄɨ³ýÌØÊâ×Ö·ûµÄÒªÁ죬ÈçʹÓÃhtmlspecialcharsº¯Êý¶ÔÓû§ÊäÈë¾ÙÐÐתÒåµÈ¡£ÎªÈ·±£³ÌÐòµÄÇå¾²ÐÔ£¬ÎÒÃÇÐèҪƾ֤ÏÖÕæÏàÐÎÑ¡ÔñÊʺϵÄÒªÁì¾ÙÐÐÏÖʵ¿ª·¢¡£
ÒÔÉϾÍÊÇthinkphpÔõÑùɨ³ýÌØÊâ×Ö·ûµÄÏêϸÄÚÈÝ£¬¸ü¶àÇë¹Ø×¢±¾ÍøÄÚÆäËüÏà¹ØÎÄÕ£¡