我們利用了php自帶的Magic Quotes來判斷是否是開啟了,如果是就stripslashes否則就用mysql_real_escape_string來過濾,實例代碼如下:
- //如果Magic Quotes功用啟用
- //開源代碼Vevb.com
- if (get_magic_quotes_gpc()) {
- $name = stripslashes($name);
- }else{
- $name = mysql_real_escape_string($name);
- }
- mysql_query("SELECT * FROM users WHERE name='{$name}'");
注:mysql_real_escape_string函數(shù)要等到mysql數(shù)據(jù)庫連接成功才有效.
新聞熱點
疑難解答