php°²È«-²»ÓùýÂËmysqlÓïÑÔ°²È«Âð£¿
PHPÖУ¬Ê¹ÓÃmysqlÊý¾Ý¿â,Linuxϵͳ¡£ ÔÚʹÓÃËÑË÷¹¦ÄÜʱ£¬Ö±½ÓÖ´ÐÐÕâÑùµÄÓï¾ä°²È«Â𣿠$keyword=$_POST["keyword"]; $sql="select * from abc where a_name like '%$keyword%'"; $rs=mysql_query($sql); ..... Èç¹û²»°²È«£¬Ó¦¸ÃÔõô¹ýÂË£¿Ð»Ð»
²»ÊÇ×ö¿ª·¢µÄ ¶ÔÕâ¸ö²»ÊìϤ $keyword = trim($keyword); $keyword = ereg_replace('([\'%;])', '\\\1', $keyword); ²»°²È«,¼ÙÈç±íµ¥ÊäÈë: \Ö®ÀàµÄ,sqlÓï¾ä¾Í³ö´í,¼ÙÈçû´¦ÀíºÃ±¨´í,Hacker¾Í¿ÉÒÔ¿´µ½ÔʼµÄsqlÓï¾ä,½øÒ»²½·ÖÎöÄãµÄ±í½á¹¹,È»ºó... Ò»°ãÕâÑùŪÏÂÓ¦¸Ã¾Í¿ÉÒÔÁË: $keyword=mysql_escape_string($_POST["keyword"]); ¶ÔÄãµÄkeywordµÄÄÚÈݽøÐмì²é¡£ ±ÈÈ罫һЩΣÏÕ×Ö·û½øÐÐתÒ壬Èç¹ûȷʵÐèÒªlike ÕâЩΣÏÕ×Ö·ûÄǾÍÒªÁíÏë°ì·¨¡£ ×ÜÖ®ÏÈ¿´Ò»ÏÂÊý¾Ý×¢ÈëÖ®ÀàµÄÎÄÕ¡£ Ö»ÒªÉæ¼°²Ù×÷Êý¾Ý¿âµÄ´úÂ룬 ²»¹ýÂ˶¼²»°²È«£¬ ³ý·ÇÄãÏëÁôºóÃÅ¡£ ²»°²È«£¬È¥²Î¿¼Ò»Ï´óÐÍCMSµÄ²ÎÊý¹ýÂË£¬ºÜÈÝÒ×ÌáÈ¡³öÀ´µÄ ÔÙ²¹³äһϣ¬´æÔÚSQL×¢Èë©¶´ÒýÓà PHPÖУ¬Ê¹ÓÃmysqlÊý¾Ý¿â,Linuxϵͳ¡£ ÔÚʹÓÃËÑË÷¹¦ÄÜʱ£¬Ö±½ÓÖ´ÐÐÕâÑùµÄÓï¾ä°²È«Â𣿠$keyword=$_POST["keyword"]; $sql="select * from abc where a_name like '%$keyword%'"; $rs=mysql_query($sql); ..... Èç¹û²»°²È«£¬Ó¦¸ÃÔõô¹ýÂË£¿Ð»Ð» $keyword=mysql_real_escape_string($_POST["keyword"]);//¿´ÊÖ²á×îºÃ£¬ÕâЩ·½ÃæµÄ֪ʶ¥Ö÷ËÑË÷һϣ¬SQL×¢Èë¡£ $sql="select * from abc where a_name
Ïà¹ØÎÊ´ð£º
1.¾«Í¨ÃæÏò¶ÔÏóµÄÉè¼ÆºÍ¿ª·¢£» 2.ÊìÁ·Ê¹ÓÃPHPÓïÑÔ(5.0+)½øÐÐÊý¾Ý¿â£¬ÍøÂçͨÐÅ£¬Îļþ¶Áд£¬°²È«»úÖÆµÈ¿ª·¢£» 3.ÊìÁ·Ê¹ÓÃMYSQL(5.0+)Êý¾Ý¿â¿ª·¢£¬°üÀ¨»ù±¾µÄÊý¾Ý¿âÉè¼Æ/ÓÅ»¯/°²È«£¬¸´ÔÓµÄT-SQLÓï¾ä±àд£¬ÊìÁ·±àдMYS ......
ÇëÎÊ£¬ÒÔÏ´úÂ룬Ϊʲô²»¹ÜÓ㿾Ístr_replaceÕâ¸öº¯Êý£¬Ì滻ôÓÐÆð×÷Óã¿ PHP code: $gg='<script type=\"text/JavaScript\"> alimama_pid=\"mm_14281022_2030060_8250750\"; alima ......
CREATE DATABASE ADDRESSLIST; USE ADDRESSLIST; DROP TABLE IF EXISTS FRIEND; CREATE TABLE FRIEND (FRIEND_ID INTEGER NOT NULL AUTO_INCREMENT PRIMARY KEY , FRIEND_NAME VARCHAR(20) NOT N ......
°²×°ÁËAPHACHE ¿ÉÊÇÔËÐÐÍøÒ³Ê²Ã´¶¼Ã»ÓÐ ¼± »¹ÏëÇëÎÊÏÂ,JSP.PHP.ASP.NET ÄǸö¹¤×ʸ߰¡, »ØÌû¾Í¼Ó·Ö »¹Òª×°php5 ×öµÃºÃ£¬Äĸö¹¤×ʶ¼¸ß¡£ http://download.csdn.net/source/1712990 Õâ¸öÀïÃæÓÐÕû¸öPHPµÄ° ......