$flow_content = eregi_replace("'","'",$flow_content); 
$flow_content = eregi_replace('"','"',$flow_content);

    1. $str=preg_replace("/\s+/", " ", $str); //过滤多余回车
    2. $str=preg_replace("/<[ ]+/si","<",$str); //过滤<__("<"号后面带空格)
    3. $str=preg_replace("/<\!--.*?-->/si","",$str); //注释
    4. $str=preg_replace("/<(\!.*?)>/si","",$str); //过滤DOCTYPE
    5. $str=preg_replace("/<(\/?html.*?)>/si","",$str); //过滤html标签
    6. $str=preg_replace("/<(\/?head.*?)>/si","",$str); //过滤head标签
    7. $str=preg_replace("/<(\/?meta.*?)>/si","",$str); //过滤meta标签
    8. $str=preg_replace("/<(\/?body.*?)>/si","",$str); //过滤body标签
    9. $str=preg_replace("/<(\/?link.*?)>/si","",$str); //过滤link标签
    10. $str=preg_replace("/<(\/?form.*?)>/si","",$str); //过滤form标签
    11. $str=preg_replace("/cookie/si","COOKIE",$str); //过滤COOKIE标签
    12. $str=preg_replace("/<(applet.*?)>(.*?)<(\/applet.*?)>/si","",$str); //过滤applet标签
    13. $str=preg_replace("/<(\/?applet.*?)>/si","",$str); //过滤applet标签
    14. $str=preg_replace("/<(style.*?)>(.*?)<(\/style.*?)>/si","",$str); //过滤style标签
    15. $str=preg_replace("/<(\/?style.*?)>/si","",$str); //过滤style标签
    16. $str=preg_replace("/<(title.*?)>(.*?)<(\/title.*?)>/si","",$str); //过滤title标签
    17. $str=preg_replace("/<(\/?title.*?)>/si","",$str); //过滤title标签
    18. $str=preg_replace("/<(object.*?)>(.*?)<(\/object.*?)>/si","",$str); //过滤object标签
    19. $str=preg_replace("/<(\/?objec.*?)>/si","",$str); //过滤object标签
    20. $str=preg_replace("/<(noframes.*?)>(.*?)<(\/noframes.*?)>/si","",$str); //过滤noframes标签
    21. $str=preg_replace("/<(\/?noframes.*?)>/si","",$str); //过滤noframes标签
    22. $str=preg_replace("/<(i?frame.*?)>(.*?)<(\/i?frame.*?)>/si","",$str); //过滤frame标签
    23. $str=preg_replace("/<(\/?i?frame.*?)>/si","",$str); //过滤frame标签
    24. $str=preg_replace("/<(script.*?)>(.*?)<(\/script.*?)>/si","",$str); //过滤script标签
    25. $str=preg_replace("/<(\/?script.*?)>/si","",$str); //过滤script标签
    26. $str=preg_replace("/javascript/si","Javascript",$str); //过滤script标签
    27. $str=preg_replace("/vbscript/si","Vbscript",$str); //过滤script标签
    28. $str=preg_replace("/on([a-z]+)\s*=/si","On\\1=",$str); //过滤script标签
    29. $str=preg_replace("/&#/si","&#",$str); //过滤script标签,如javAsCript:alert('aabb)

相关文章: