1.替换(移除)sql接受参数的特殊字符
//替换(移除)sql接受参数的特殊字符
function removeSQL($val){
$val=mysql_escape_string(trim($val));
$arr=array("'",";","=","*","delete","alter","select","and ","or ","update","unique","show","set ");
for...
12-24 3,299 views
1.替换(移除)sql接受参数的特殊字符
//替换(移除)sql接受参数的特殊字符
function removeSQL($val){
$val=mysql_escape_string(trim($val));
$arr=ar...