Hi,歡迎訪問前端老白
<form action="login.php" method="POST"> 用戶名: <input type="text" name="username"><br> 密碼: <input type="password" name="password"><br> <input type="submit" value="提交"> </form>
$username = $_POST['username']; $password = $_POST['password'];
if(empty($_POST['username']) || empty($_POST['password'])){ //用戶名或密碼為空,處理異常情況 } else{ //用戶名和密碼都不為空,可以進行登錄驗證 }
" ' OR '1'='1"
SELECT * FROM users WHERE username='' OR '1'='1' AND password=''
$username = addslashes($_POST['username']); $password = addslashes($_POST['password']);
<script>alert('XSS攻擊')</script>
$username = htmlspecialchars($_POST['username'], ENT_QUOTES, 'UTF-8', false); $password = htmlspecialchars($_POST['password'], ENT_QUOTES, 'UTF-8', false);
老白網絡 (http://www.lofty888.cn/) 前端 后端 zblog主題.網站地圖xml