PHP SQL ×¢Èë¹¥»÷µÄ¼¼ÊõʵÏÖÒÔ¼°Ô¤·À°ì·¨
¡¡×î½üÔÚÕÛÌÚ PHP + MYSQL
µÄ±à³Ì¡£Á˽âÁËһЩ PHP SQL ×¢Èë¹¥»÷
µÄ֪ʶ£¬ÓÚÊÇдÁËÕâƪÎÄÕ¡¡http://www.xiaohui.com/weekly/20070314.htm£¬×ܽáһϾÑé¡£ÔÚÎÒ¿´À´£¬Òý·¢ SQL ×¢Èë¹¥»÷
µÄÖ÷ÒªÔÒò£¬ÊÇÒòΪÒÔÏÂÁ½µãÔÒò£º
¡¡¡¡1. php ÅäÖÃÎļþ php.ini ÖÐµÄ magic_quotes_gpc
Ñ¡ÏîûÓдò¿ª£¬±»ÖÃΪ off
¡¡¡¡2. ¿ª·¢ÕßûÓжÔÊý¾ÝÀàÐÍ
½øÐмì²éºÍתÒå
¡¡¡¡²»¹ýÊÂʵÉÏ£¬µÚ¶þµã×îΪÖØÒª¡£ÎÒÈÏΪ, ¶ÔÓû§ÊäÈëµÄÊý¾ÝÀàÐͽøÐмì²é£¬Ïò MYSQL Ìá½»ÕýÈ·µÄÊý¾ÝÀàÐÍ£¬ÕâÓ¦¸ÃÊÇÒ»¸ö web ³ÌÐòÔ±×î×î»ù±¾µÄËØÖÊ
¡£µ«ÏÖʵÖУ¬³£³£ÓÐÐí¶àС°×ʽµÄ Web ¿ª·¢ÕßÍüÁËÕâµã, ´Ó¶øµ¼ÖºóÃŴ󿪡£
¡¡¡¡ÎªÊ²Ã´ËµµÚ¶þµã×îΪÖØÒª£¿ÒòΪÈç¹ûûÓеڶþµãµÄ±£Ö¤£¬magic_quotes_gpc Ñ¡Ï²»ÂÛΪ on£¬»¹ÊÇΪ off£¬¶¼ÓпÉÄÜÒý·¢ SQL ×¢Èë¹¥»÷¡£ÏÂÃæÀ´¿´Ò»Ï¼¼ÊõʵÏÖ£º
¡¡Ò». magic_quotes_gpc = Off ʱµÄ×¢Èë¹¥»÷
¡¡¡¡magic_quotes_gpc = Off
ÊÇ php ÖÐÒ»Öַdz£²»°²È«µÄÑ¡Ïа汾µÄ php ÒѾ½«Ä¬ÈϵÄÖµ¸ÄΪÁË On¡£µ«ÈÔÓÐÏ൱¶àµÄ·þÎñÆ÷µÄÑ¡ÏîΪ off¡£±Ï¾¹£¬ÔٹŶµÄ·þÎñÆ÷Ò²ÊÇÓÐÈËÓõġ£
¡¡¡¡µ±magic_quotes_gpc = On¡¡Ê±£¬Ëü»á½«Ìá½»µÄ±äÁ¿ÖÐËùÓÐµÄ '(µ¥ÒýºÅ)¡¢"(Ë«ºÅºÅ)¡¢\(·´Ð±Ïß)¡¢¿Õ°××Ö·û£¬¶¼ÎªÔÚÇ°Ãæ×Ô¶¯¼ÓÉÏ \¡£ÏÂÃæÊÇ php µÄ¹Ù·½ËµÃ÷£º
magic_quotes_gpc
boolean
Sets the magic_quotes state for GPC (Get/Post/Cookie) operations. When
magic_quotes are on, all ' (single-quote), " (double quote), \
(backslash) and NUL's are escaped with a backslash automatically
¡¡¡¡Èç¹ûûÓÐתÒ壬¼´ off Çé¿öÏ£¬¾Í»áÈù¥»÷ÕßÓлú¿É³Ë¡£ÒÔÏÂÁвâÊԽű¾ÎªÀý£º
http://www.xiaohui.com/weekly/20070314.htm
<?
if ( isset($_POST["f_login"] ) )
{
// Á¬½ÓÊý¾Ý¿â...
// ...´úÂëÂÔ...
// ¼ì²éÓû§ÊÇ·ñ´æÔÚ
$t_strUname = $_POST["f_uname"];
$t_strPwd = $_POST["f_pwd"];
$t_strSQL = "SELECT * from tbl_users WHERE username='$t_strUname' AND password = '$t_strPwd' LIMIT 0,1";
if ( $t_hRes = mysql_query($t_strSQL) )
{
// ³É¹¦²éѯ֮ºóµÄ´¦Àí. ÂÔ...
}
}
?>
<html><head><title>sample test</title></head>
<body>
<form method=post action="">
Username: <input type
Ïà¹ØÎĵµ£º
СµÜÏëÎʸöÎÊÌ⣬ÔÚSQL Server 2005ÉÏ£¬½¨Á¢Ö÷¼üµÄͬʱ¾Í»áĬÈÏÔÚÖ÷¼üÉÏÉèÖþ۴ØË÷Òý£¬ÄÇôÄÜ·ñÔÚÒ»¸ö×Ö¶ÎÉÏÉèÖÃÖ÷¼üºÍΨһÐÔË÷Òý£¨Unique£©£¬µ«ÊǰѾ۴ØË÷ÒýÉèÖõ½ÁíÒ»¸ö×Ö¶ÎÉÏ£¿
¾Ù¸ö¼òµ¥µÄÀý×Ó£¬±ÈÈçÎÒÓиö±í½ÐTableTest£¬±íÀïÓÐÁ½¸ö×ֶΣ¬id,date£¬±¾À´idÊÇÖ÷¼üµÄ£¬ÎÒÏÖÔÚÏë°Ñ¾Û´ØË÷ÒýÉèÖõ½date×Ö¶ÎÉÏ¡£
ÎÒÏÈɾ³ýÖ ......
<?php
$zip_filename = "testpm.zip";
$zip_filename = key_exists('zip', $_GET) && $_GET['zip']?$_GET['zip']:$zip_filename;
$zip_filepath = str_replace('\\', '/', dirname(__FILE__)) . '/' . $zip_filename;
if(!is_file($zip_filepath))
{
die('Îļþ"'.$zip_ ......
//È¥³ý script ½Å ±¾
function delScript($string){
$pregfind = array("/<script.*>.*<\/script>/siU",'/on(mousewheel|mouseover|click|load|onload|submit|focus|blur)="[^"]*"/i');
$pregreplace = array('','');
$string = preg_replace($pregfind, $pregreplace, $string);
return $str ......
PHPµÄËã·¨¶¼ÓÐÄÄЩÄØ£¿
ÎÒ»¹¼ÇµÃÉÏ´óѧÄÇ»áѧÊý¾Ý½á¹¹Ê±£¬Á˽âÁË:˳Ðò·¨¡¢Ã°ÅÝ·¨¡¢¶þ·Ö·¨ÒÔ¼°¶ÔÏßÐÔ±íÒÔ¼°Êý¾ÝÈëÕ»¡¢³öÕ»µÄ²Ù×÷¡£
PHPÖеÄ˳Ðò·¨¾ÍÊǶÔÊý×éÔªËصÄÖðÒ»±È½Ï¶øµÃµ½µÄ¡£
ÀýÈ磺
<?php
function order($php,$k)
{
$n = count($php); //¼ÆËãÊý×é¸öÊý
$php ......
¡¾Ê¾Àý1.1¡¿ ²éѯ¹ÍÔ±±àºÅΪ7788µÄ¹ÍÔ±ÐÕÃûºÍ¹¤×Ê¡£
²½Öè1£ºÓÃSCOTT/TIGERÕË»§µÇ¼SQL*Plus¡£
²½Öè2£ºÔÚÊäÈëÇøÊäÈëÒÔϳÌÐò£º
/*ÕâÊÇÒ»¸ö¼òµ¥µÄʾÀý³ÌÐò*/
SET SERVEROUTPUT ON
DECLARE--¶¨Ò岿·Ö±êʶ
v_name VARCHAR2 ......