亚洲国产日韩欧美一区二区三区,精品亚洲国产成人av在线,国产99视频精品免视看7,99国产精品久久久久久久成人热,欧美日韩亚洲国产综合乱

How to intercept numeric SQL injection? Is it valid to verify if it is a number?
顧及
顧及 2020-05-05 20:19:27
0
1
1219

Test that adding single and double quotation marks to the sql query can still cause sql injection.

As the title states, can SQL injection be intercepted assuming that the verification parameter is a number?

if (!is_numeric($id)) {
exit('非法'); 
        }

SQL injection is no longer possible in such verification tests, but is this absolutely safe?

Xiaobai asks for help.

顧及
顧及

reply all(1)
路邊的小螞蟻i

Use the framework's sql statement encapsulation method. The framework will prevent you from sql injection. When you have enough knowledge and experience, you can study these

Latest Downloads
More>
Web Effects
Website Source Code
Website Materials
Front End Template