[ת]PHP SQL ×¢Èë¹¥»÷µÄ¼¼ÊõʵÏÖÒÔ¼°Ô¤·À°ì·¨(4)
define("XH_PARAM_INT",0); define("XH_PARAM_TXT",1); function PAPI_GetSafeParam($pi_strName, $pi_Def = "", $pi_iType = XH_PARAM_TXT) { if ( isset($_GET[$pi_strName]) ) $t_Val = trim($_GET[$pi_strName]); else if ( isset($_POST[$pi_strName])) $t_Val = trim($_POST[$pi_strName]); else return $pi_Def; // INT if ( XH_PARAM_INT == $pi_iType) { if (is_numeric($t_Val)) return $t_Val; else return $pi_Def; } // String $t_Val = str_replace("&", "&",$t_Val); $t_Val = str_replace("<", "<",$t_Val); $t_Val = str_replace(">", ">",$t_Val); if ( get_magic_quotes_gpc() ) { $t_Val = str_replace("\\\"", """,$t_Val); $t_Val = str_replace("\\''", "'",$t_Val); } else { $t_Val = str_replace("\"", """,$t_Val); $t_Val = str_replace("'", "'",$t_Val); } return $t_Val; }ÔÚÕâ¸öº¯ÊýÖУ¬ÓÐÈý¸ö²ÎÊý£º
$pi_strName: ±äÁ¿Ãû $pi_Def: ĬÈÏÖµ $pi_iType: Êý¾ÝÀàÐÍ¡£È¡ÖµÎª XH_PARAM_INT, XH_PARAM_TXT, ·Ö±ð±íʾÊýÖµÐͺÍÎı¾ÐÍ¡£¡¡Èç¹ûÇëÇóÊÇÊýÖµÐÍ£¬ÄÇôµ÷Óà is_numeric() ÅжÏÊÇ·ñΪÊýÖµ¡£Èç¹û²»ÊÇ£¬Ôò·µ»Ø³ÌÐòÖ¸¶¨µÄĬÈÏÖµ¡£
¡¡¡¡¼òµ¥Æð¼û£¬¶ÔÓÚÎı¾´®£¬ÎÒ½«Óû§ÊäÈëµÄËùÓÐΣÏÕ×Ö·û£¨°üÀ¨HTML´úÂ룩£¬È«²¿×ªÒå¡£ÓÉÓÚ php º¯Êý addslashes()´æÔÚ©¶´£¬ÎÒÓà str_replace()Ö±½ÓÌæ»»¡£get_magic_quotes_gpc() º¯ÊýÊÇ php µÄº¯Êý£¬ÓÃÀ´ÅÐ¶Ï magic_quotes_gpc Ñ¡ÏîÊÇ·ñ´ò¿ª¡£
¡¡¡¡¸Õ²ÅµÚ¶þ½ÚµÄʾÀý£¬´úÂë¿ÉÒÔÕâÑùµ÷Óãº
<? if ( isset($_POST["f_login"] ) ) { // Á¬½ÓÊý¾Ý¿â... // ...´úÂëÂÔ... // ¼ì²éÓû§ÊÇ·ñ´æÔÚ $t_strUid = PAPI_GetSafeParam("f_uid", 0, XH_PARAM_INT); $t_strPwd = PAPI_GetSafeParam("f_pwd", "", XH_PARAM_TXT); $t_strSQL = "SELECT * FROM tbl_users WHERE uid=$t_strUid AND password = '$t_strPwd' LIMIT 0,1"; if ( $t_hRes = mysql_query($t_strSQL) ) { // ³É¹¦²éѯ֮ºóµÄ´¦Àí. ÂÔ... } } ?>ÕâÑùµÄ»°£¬¾ÍÒѾÏ൱°²È«ÁË¡£PAPI_GetSafeParamµÄ´úÂëÓе㳤£¬µ«ÎþÉüÕâµãЧÂÊ£¬¶Ô±£Ö¤°²È«£¬ÊÇÖµµÃµÄ¡£Ï£Íû´ó¼Ò¶àÅúÆÀÖ¸Õý¡££º£©
ÍƼöÐÅÏ¢
- ¡¾ÊÓƵ²¥·Å¡¿JplayerÊÓƵ²¥·ÅÆ÷µÄʹÓÃ
- memcacheÄÚ´æÔÀí
- Memcache¼¼Êõ·ÖÏí£º½éÉÜ¡¢Ê¹Óᢴ洢¡¢Ëã·¨¡¢ÓÅ»¯....
- php³£ÓÃÕýÔò±í´ïʽ
- phpÐÔÄܼà²âÄ£¿éXHProf
- ÈÃCI¿ò¼ÜÖ§³Öservice²ã
- ʹÓÃPHPÉú³É´øLOGOµÄ¸öÐÔ»¯¶þάÂëͼÏñ
- ¹ØÓÚCodeIgniterÄã¿ÉÄܲ»ÖªµÀµÄ5¸ö֪ʶµã
- Memcache ºÁÃ뼶³¬Ê±¼°ÆäËû³£¼ûÎÊÌâ»ã×Ü
- [PHP±Ê¼Ç]PHPQueryÒ»¸ö´¦ÀíDOMµÄÀûÆ÷
ÈÈÃÅÐÅÏ¢
- nohup: redirecting stderr to stdou....
- ʹÓÃlog_formatΪNginx·þÎñÆ÷ÉèÖøüÏêϸµÄÈÕÖ¾¸ñʽ
- jquery easyUI--dataGrid-Json
- [Ô´´]·ÂGoogle Reader¡¢ÐÂÀË΢²©¡¢ÌÚѶ΢²©µ....
- ÀûÓÃKeepalived+mysql¹¹½¨¸ß¿ÉÓÃMySQLË«Ö÷×Ô¶....
- Nginx+keepalivedʵÏÖ¸ºÔؾùºâºÍË«»úÈȱ¸¸ß¿ÉÓÃ
- jqueryʵÏÖÒ³Ãæ¼ÓÔؽø¶ÈÌõ
- Rolling cURL: PHP²¢·¢×î¼Ñʵ¼ù
- codeigniter ·ÓÉÖÕ¼«ÓÅ»¯(url rewrite)
- linuxÏÂÉèÖÃsshÎÞÃÜÂëµÇ¼
×î½ü¸üÐÂ
- PHP»ñÈ¡Óû§µÄÕæʵIP£¬²¢ÅжÏÊÇ·ñÄÚÍøIP
- PHP ´íÎóÈÕÖ¾ error_log
- ÀûÓÃbigpipe»úÖÆʵÏÖÒ³ÃæÄ£¿éµÄÒì²½äÖȾ chunked¼¼Êõ
- php¿ØÖÆÎļþÏÂÔØËÙ¶È
- js + php ¶ÁÈ¡¡¢²¥·ÅÊÓƵÁ÷ ¼æÈÝfirefox£¬c....
- ¡¾ÊÓƵ²¥·Å¡¿JplayerÊÓƵ²¥·ÅÆ÷µÄʹÓÃ
- UNICODE Óë UTF-8 µÄ¹Øϵ
- memcacheÄÚ´æÔÀí
- Memcache¼¼Êõ·ÖÏí£º½éÉÜ¡¢Ê¹Óᢴ洢¡¢Ëã·¨¡¢ÓÅ»¯....
- phpʹÓÃmb_detect_encoding¼ì²â×Ö·û´®±àÂë
ÆÀÂÛ