发布时间:2024-04-07 10:30:01
demoUserID = getrequestString("userID"); demoSQL = "SELECT * FROM users WHERE id =" + demoUserID;
236893238 OR 1=1
SELECT * FROM employee WHERE id = 236893238 OR 1=1;
1=1
SELECT * FROM employee WHERE (username="" or 1=1) AND (password="" or 1=1);
;
SELECT * FROM employee; DROP TABLE employee_add;
_
-
if (preg_match("/^[\x{4e00}-\x{9fa5}0-9A-Za-z_\-]{2,20}$/u", $_POST['username'], $matches)) { $result = mysql_query("SELECT * FROM user WHERE name = $matches[0]"); } else { echo "Tips from www.365tools.cn: User name not accepted!"; }
\
'
"
// 去除斜杠 if (get_magic_quotes_gpc()) { $name = stripslashes($name); } // 对特殊字符进行转义 $name = mysql_real_escape_string($name); mysql_query("SELECT * FROM user WHERE name='{$name}'");
%
$sub = addcslashes(mysql_real_escape_string("%str"), "%_"); // 转换以后的 $sub == \%str\_ mysql_query("SELECT * FROM messages WHERE subject LIKE '{$sub}%'");