使用 PHP 清理用户输入的方法有哪些?\

phpprogrammingserver side programming更新于 2025/10/7 8:22:17

输入清理是 PHP 中一个有趣的概念。清理意味着转义输入中未经授权的字符。让我们学习一些以安全可靠的方式处理输入的最佳实践。

在 mysqli 语句中使用 real_escape_string() 函数。

示例

<?php
   $conn= new mysqli("localhost", "root","","testdb");
   $street = $conn->real_escape_string($_POST['street']);
?>

我们可以使用 htmlentities() 和 html_entity_decode() 将数据插入数据库并在浏览器中显示。

示例

<?php
   $data['message'] = htmlentities($message);//插入数据库时
   echo html_entity_decode($data['message']); //在浏览器中显示时
?>

使用 escapeshellarg 在命令提示符中过滤用户输入。

示例 −

<?php system('ls '.escapeshellarg($data['dir']));?>

相关文章