PHP's new input_filter does not read $_GET or $_POST arrays

前端 未结 6 1487
温柔的废话
温柔的废话 2020-12-16 00:28

In PHP 5.2 there was a nice security function added called \"input_filter\", so instead of saying:

$name = $_GET[\'name\'];

you can now say

6条回答
  •  佛祖请我去吃肉
    2020-12-16 01:03

    PHP's new input_filter does not read $_GET or $_POST arrays. If you are overwriting Global's (like,$_GET,$_POST) then Don't go for filter_input. Instead use filter_var ( $_GET['name'], FILTER_SANITIZE_STRING ) by manually passing variable.

提交回复
热议问题