使用 PHP 清理用户输入的方法有哪些?\
phpprogrammingserver side programming更新于 2025/10/7 8:22:17
输入清理是 PHP 中一个有趣的概念。清理意味着转义输入中未经授权的字符。让我们学习一些以安全可靠的方式处理输入的最佳实践。
在 mysqli 语句中使用 real_escape_string() 函数。
示例
<?php
$conn= new mysqli("localhost", "root","","testdb");
$street = $conn->real_escape_string($_POST['street']);
?>
我们可以使用 htmlentities() 和 html_entity_decode() 将数据插入数据库并在浏览器中显示。
示例
<?php $data['message'] = htmlentities($message);//插入数据库时 echo html_entity_decode($data['message']); //在浏览器中显示时 ?>
使用 escapeshellarg 在命令提示符中过滤用户输入。
示例 −
<?php system('ls '.escapeshellarg($data['dir']));?>

