【发布时间】:2015-10-27 08:54:35
【问题描述】:
我的表单输入消毒功能:
function clean_input($data)
{
$data = trim($data);
$data = strip_tags($data);
$data = stripslashes($data);
$data = htmlspecialchars($data);
return $data;
}
我的 SQL 行:
$q = "SELECT * FROM users WHERE username = {mysqli_real_escape_string ('$username')} AND password = {mysqli_real_escape_string('$password')}";
$r = mysqli_query($dbc, $q);
这是正确的用法吗?
【问题讨论】:
标签: php mysql security sql-injection sanitization