php教程 批量過濾非法字元
function testAddslashes($array) {
if(!get_magic_quotes_gpc()) {
if(is_array($array)) {
foreach($array as $key => $val) {
$array[$key] = testAddslashes($val);
}
} else {
$array = addslashes($array);
}
$array=str_replace("&#x","& # x",$array); 過濾一些不安全
字元s
$array=str_replace("<","<",$array); 過濾<
}
return $array;
}
if( $_POST)
{
print_r( $_POST );
echo '過濾前<hr /> ';
$_POST = testAddslashes($_POST);
echo '<hr />過濾後<br />';
echo $_POST['textfield'];
}
?>
<! DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"HTTP://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="HTTP://www.w3.org/1999/xhtml">
<head>
<meta HTTP-equiv="Content-Type" content="text/html; charset=gb2312" />
<title>無標題文檔</title>
</head>
<body>
<form action="" method="post" enctype="multipart/form-data" name="form1"
id="form1">
<label>
<input type="text" name="textfield" />
</ label>
<p>
<label>
<input type="text" name= "textfield2" />
</label>
<label></label>
</p>
<p>
<label>
<input type=" submit" name="Submit" value="提交" />
</label>
</p>
</form>
</body>
</html>