首页 > 代码库 > 从POST和GET和request过滤掉SQL注入

从POST和GET和request过滤掉SQL注入

替换掉sql关键字,进行处理

function sqlCheck($parameter){    $arr = array();    foreach($parameter as $k=>$v){        $arr[$k] = sprintf("%s",preg_replace(‘/\b(=|<|>|and|or|;|where|from|not|HAVING|select)\b/im‘,‘‘,$v));    }    return $arr;}$_GET = sqlCheck($_GET);$_POST = sqlCheck($_POST);$_REQUEST = sqlCheck($_REQUEST);

从POST和GET和request过滤掉SQL注入