-----------------------------------------------------------------------------------------
防止查询的sql攻击 => 对关键词进行过滤(代码局部)
------------------------@chenwei
$k = $_REQUEST['k'];
$k = addslashes($k); //转义:单引号,双引号,反斜线,NULL
立即学习“PHP免费学习笔记(深入)”;
$k = str_replace('%', '\%', $k);
$k = str_replace('_', '\_', $k);
$sql = "select * from users where name like '%$k%'";
if(!empty($k)){
$res = mysql_query($sql, $con) or die(mysql_error());
if($row = mysql_fetch_assoc($res)){
foreach($row as $k=>$v){
echo $row[$k].':'.$row[$v].'
';
}
}
}else{
echo '******';
}
----------------------------------------------------------------------------------------
PHP怎么学习?PHP怎么入门?PHP在哪学?PHP怎么学才快?不用担心,这里为大家提供了PHP速学教程(入门到精通),有需要的小伙伴保存下载就能学习啦!
Copyright 2014-2025 https://www.php.cn/ All Rights Reserved | php.cn | 湘ICP备2023035733号