替换掉sql关键字,进行处理

// sql参数过滤
function sqlCheck($paramater){
    $arr = array();
    foreach($paramater as $k=>$v){
        if(is_array($v)){
            foreach($v as $u){
                $arr[$k][] = $u;
            }
        }else{
            $arr[$k] = sprintf("%s",preg_replace('/\b(=|<|>|and|or|;|where|from|not|HAVING|select)\b/im','',$v));
        }
    }
    return $arr;
}
$_GET = sqlCheck(&$_GET);
$_POST = sqlCheck(&$_POST);
$_REQUEST = sqlCheck(&$_REQUEST);

 

相关文章:

  • 2022-01-28
  • 2022-12-23
  • 2018-08-16
  • 2021-11-02
  • 2022-12-23
  • 2022-12-23
  • 2022-12-23
  • 2021-09-08
猜你喜欢
  • 2021-10-21
  • 2022-12-23
  • 2022-12-23
  • 2021-08-24
  • 2022-12-23
  • 2022-12-23
相关资源
相似解决方案