提问人:ahmedg 提问时间:4/19/2020 更新时间:4/19/2020 访问量:61
这个函数足以防止SQL注入吗?[复制]
Is this function enough for preventing SQL Injection? [duplicate]
问:
我创建了这个简单的函数,并想知道它是否足以防止SQL注入。
$sub_username = encr(mysqli_real_escape_string($conn, $_POST['username']));
$sub_password = encr(mysqli_real_escape_string($conn, $_POST['password']));
$sql = "SELECT password FROM login WHERE username='$sub_username'";
$result = mysqli_query($conn, $sql);
function encr($data) {
$data = trim($data);
$data = stripslashes($data);
$data = htmlspecialchars($data);
}
答: 暂无答案
评论
password_hash()