Efficiently sanitize user entered text

前端 未结 3 1175
無奈伤痛
無奈伤痛 2020-12-09 06:28

I have a html form that accepts user entered text of size about 1000, and is submitted to a php page where it will be stored in mysql database. I use PDO with prepared state

3条回答
  •  暗喜
    暗喜 (楼主)
    2020-12-09 07:02

    There are two simple things you need to do to be safe:

    • Use prepared statements or escape the data correctly.
    • When outputting to HTML, always escape using htmlspecialchars( ).

提交回复
热议问题