我想做的就是將 html 注入轉(zhuǎn)義到我的輸入文本框中。我沒有正確使用 htmlentities 嗎?代碼:<?php require_once "pdo.php"; // Demand a GET parameter if ( ! isset($_GET['name']) || strlen($_GET['name']) < 1 ) { die('Name parameter missing'); } else { $username = $_GET['name']; } // If the user requested logout go back to index.php if ( isset($_POST['logout']) ) { header('Location: index.php'); return; } $year = isset($_POST['year']) ? $_POST['year'] : ''; $mileage = isset($_POST['mileage']) ? $_POST['mileage'] : ''; $make = isset($_POST['make']) ? $_POST['make'] : ''; $failure = false; $success = false; if ( isset($_POST['make']) && isset($_POST['year']) && isset($_POST['mileage'])) { //$year = $_POST['year']; //$mileage = $_POST['mileage']; //$make = $_POST['make']; if ( strlen($make) < 1){ $failure = "Make is Required"; } else { if (is_numeric($year) and is_numeric($mileage) ){ error_log("year is a number ".$_POST['year']); error_log("Mileage is a number ".$_POST['mileage']); $sql = "INSERT INTO autos (make, year, mileage) VALUES (:make, :year, :mileage)"; $stmt = $pdo->prepare($sql); $stmt->execute(array( ':make' => $make, ':year' => $year, ':mileage' => $mileage)); $success = "Record Inserted"; } else { $failure = "Mileage and Year must be numeric"; error_log("year or mileage is not a number year=".$_POST['year']); error_log("Mileage or year is not a number mileage=".$_POST['mileage']); } } }輸出不會轉(zhuǎn)義見截圖:
1 回答

江戶川亂折騰
TA貢獻(xiàn)1851條經(jīng)驗(yàn) 獲得超5個贊
將 htmlspecialchars 添加到 (make) 給了我我正在尋找的結(jié)果。感謝任何人嘗試幫助我。
- 1 回答
- 0 關(guān)注
- 204 瀏覽
添加回答
舉報
0/150
提交
取消