php´úÂëÓÅ»¯
ÏÂÃæÕâһС¶Î“ÁÓÖÊ”µÄPHP´úÂëÊÇÒ»µÀ¼ò»¯Á˵IJâÊÔÌâ¡£ÕâÖÖÎÊÌâ¾ÍÏñÔÚÎÊ£ºÄã¸ÃÔõÑùÓÅ»¯Õâ¶Î´úÂ룿
<?
echo(”<p>Search results for query: ” .
$_GET['query'] . “.</p>”);
?>
¡¡¡¡Õâ¶Î´úÂëµÄÖ÷ÒªÎÊÌâÔÚÓÚËü°ÑÓû§Ìá½»µÄÊý¾ÝÖ±½ÓÏÔʾµ½ÁËÍøÒ³ÉÏ£¬´Ó¶ø²úÉúXSS©¶´¡£ÆäʵÓкܶ෽·¨¿ÉÒÔÌî²¹Õâ¸ö©¶´¡£ÄÇô£¬Ê²Ã´´úÂëÊÇÎÒÃÇÏëÒªµÄÄØ£¿
<?
echo(”<p>Search results for query: ” .
htmlspecialchars($_GET['query']) . “.</p>”);
?>
¡¡¡¡ÕâÊÇ×îµÍÒªÇó¡£XSS©¶´ÓÃhtmlspecialcharsº¯ÊýÌî²¹ÁË£¬´Ó¶øÆÁ±ÎÁË·Ç·¨×Ö·û¡£
<?php
if (isset($_GET['query']))
{
echo ‘<p>Search results for query: ‘,
htmlspecialchars($_GET['query'], ENT_QUOTES), ‘.</p>’;
}
?>
¡¡¡¡ÄÜд³öÕâÑù´úÂëµÄÈËÓ¦¸ÃÊÇÎÒÏëҪ¼ÓõÄÈËÁË¡£
<?±»Ìæ»»³ÉÁË<?php£¬ÕâÑù¸ü·ûºÏXML¹æ·¶¡£
ÔÚÊä³ö$_GET['query']µÄֵ֮ǰÏÈÅжÏËüÊÇ·ñΪ¿Õ¡£
echoÃüÁîÖжàÓàµÄÀ¨ºÅ±»È¥µôÁË¡£
×Ö·û´®Óõ¥ÒýºÅÏÞ¶¨£¬´Ó¶ø½ÚÊ¡ÁËPHP´Ó×Ö·û´®ÖÐËÑË÷¿ÉÌæ»»µÄ±äÁ¿µÄʱ¼ä¡£
ÓöººÅ´úÌæ¾äºÅ£¬½ÚÊ¡ÁËechoµÄʱ¼ä¡£
½«ENT_QUOTES±êʶ´«µÝ¸øhtmlspecialcharsº¯Êý£¬´Ó¶ø±£Ö¤µ¥ÒýºÅÒ²»á±»×ªÒå¡£ËäÈ»Õâ²¢ÊÇ×îÖ÷ÒªµÄ£¬µ«Ò²ËãÊÇÒ»¸öÁ¼ºÃÏ°¹ß¡£
¡¡¡¡¿ÉϧµÄÊÇ£¬Äܸø³öÕâÑùÈÃÈËÂúÒâ´ð¸´µÄ³ÌÐòÔ±ÉÙÖ®ÓÖÉÙ
Ïà¹ØÎĵµ£º
ϵͳ°æ±¾±È½Ï
mixed version_compare ( string version1, string version2 [, string operator] )
version_compare('5.1','<'); //±È½Ïµ±Ç°°æ±¾ÊÇ·ñСÓÚ5.1
ÊÇ·ñ¿ªÆô×Ô¶¯/
get_magic_quotes_gpc()
return 1 on: will add slash.
return 0 off:willn't add.
if(get_magic_quotes_gpc()) {
$cm ......
// ÎÒ¿´¹ýµÄÁ½±¾Êé PHP µÄÊéÖÐÌá¼°µ½ PHP6 µÄÐÂÌØÐÔ£¬ÆäÖÐÁ½¸öÊÇ namespace ºÍ unicode£¬
// ´Ó PHP5.3 ¿ªÊ¼£¬php ÒѾ֧³Ö namespace ÁË; ¶ø Unicode ÔÚ PHP5.3 Öл¹Ã»Óз¢²¼¡£
//
// ¿´Êé¿´µ½ PHP µÄ¶à×Ö½Ú´¦Àí£¬Ï뵽ǰ¶Îʱ¼ä»¹»á×Ô¼º½ØÈ¡ ÖÐÓ¢»ìºÏµÄ×Ö·û´®£¬ÄÇʱºò»¨Á˺ܳ¤Ê±¼äÀ´¿´ utf£8£¬
// gbk, gb2312, gb180 ......
1¡¢Ä£°åµÄÓÉÀ´
ÔÚûÓÐÄ£°å¼¼Êõ֮ǰ£¬Ê¹ÓÃPHP¿ª·¢³ÌÐò£¬Í¨³£¶¼ÊÇphp´úÂëºÍhtml»ì±àÔÚÒ»Æð¡£±ÈÈç˵ÐÂÎÅÁÐ±í£¬ºÜ¿ÉÄܾÍÊÇÒ»¸önewslist.phpÒ³Ã棬½á¹¹ÈçÏ£º
<?
//´ÓÊý¾Ý¿âÖжÁÈ¡³öÒªÏÔʾµÄÐÂÎżÇ¼
?>
<html>
<head>……..
</head>
<body>
<?
While ($news ......
<?php
/**
* Mysql DB
*
* @author Administrator
* @package defaultPackage
*/
class MySqlDB{
private $_db;
private static $_instance;
private function __construct(&$db_type){
global $connectionstr;
$conn_db=$connectionstr[$db_type];
$this->_db=mysql_pconnect($conn ......
ÓÃPHPдһ¸ö×Ô¼ºµÄÄ£°åÒýÇæ
2009-07-11 09:51
SmartyÒ»Ö±±»ÈËÊÓΪÊǶàÓàµÄ¶«Î÷£¬ÎÒ¾õµÃÈÏΪSmarty¶àÓàµÄÈ˲ÅÊǶàÓàµÄ....²»ËµÕâЩÁË¡£½ñÌìÎҾͽ̴ó¼Òд¸öÄ£°åÒýÇ棬Èôó¼Ò¶¼¿ÉÒÔдһ¸öÊôÓÚ×Ô¼ºµÄÄ£°åÒýÇ棬¶øÇÒ¿´ÍêÕâƪÎÄÕÂÖ®ºó£¬Äã¶ÔSmartyµÄÈÏʶ»á¸ü½øÒ»²½µÄ¡£ÎÒµÄÄ£°åÒýÇæÃû½ÐStupid£¨"ɵ¹Ï"µÄÒâ˼£©£¬ÎÒ²»Ï ......