Preventing HTML and Script injections in Javascript

后端 未结 7 1822
粉色の甜心
粉色の甜心 2020-12-04 13:12

Assume I have a page with an input box. The user types something into the input box and hits a button. The button triggers a function that picks up the value typed into the

7条回答
  •  余生分开走
    2020-12-04 13:44

    Try this method to convert a 'string that could potentially contain html code' to 'text format':

    $msg = "
    "; $safe_msg = htmlspecialchars($msg, ENT_QUOTES); echo $safe_msg;

    Hope this helps!

提交回复
热议问题