【发布时间】:2021-03-19 17:24:42
【问题描述】:
这足够安全吗?还是应该改进?此代码是否受 SQL 注入保护? (PHP)
if (isset($_POST['mailSet'])) {
$asd=filter_input(INPUT_POST, 'TypeM', FILTER_SANITIZE_NUMBER_INT);
$zxc=filter_input(INPUT_POST, 'mailFor', FILTER_SANITIZE_NUMBER_INT);
global $wpdb;
try {
$wpdb->get_row($wpdb->prepare("UPDATE mail_sttng set setting_val=%d
WHERE setting=1
", $asd));
$wpdb->get_row($wpdb->prepare("UPDATE mail_sttng set setting_val=%d
WHERE setting=2
", $zxc));
bla bla...
【问题讨论】:
-
缺少标签?
php或许? -
我没有包含所有代码。是的,PHP
标签: php sql wordpress code-injection protected