时间:2021-07-01 10:21:17 帮助过:7人阅读
正则过滤
if(empty($name) || !preg_match("/^[a-zA-Z0-9]{6,}$",$name)){ die(‘用户名格式错误‘); }
$db = mysqli_connect(‘localhost‘,$username,$pwd,$database); $sql = "SELECT id,name FROM user WHERE name = ? AND password = ?"; $stmt = mysqli_prepare($db,$sql); mysqli_stmt_bind_param($stmt,‘ss‘,$name,$password); mysqli_stmt_execute($stmt); mysqli_stmt_bind_result($stmt,$id,$name); mysqli_stmt_fetch($stmt);
SQL注入详解
标签:异常 通过 web exec use connect 参数 nec die