📄 用户输入过滤程序.asp
字号:
<%
strUserInput="Smith'%;EXEC master..xp_cmdshell 'dir *.exe"
strUserInput=Replace(strUserInput,"<",vbNullString)
strUserInput=Replace(strUserInput,">",vbNullString)
strUserInput=Replace(strUserInput,"""",vbNullString)
strUserInput=Replace(strUserInput,"'",vbNullString)
strUserInput=Replace(strUserInput,"%",vbNullString)
strUserInput=Replace(strUserInput,";",vbNullString)
strUserInput=Replace(strUserInput,"(",vbNullString)
strUserInput=Replace(strUserInput,")",vbNullString)
strUserInput=Replace(strUserInput,"&",vbNullString)
strUserInput=Replace(strUserInput,"+",vbNullString)
strUserInput=Replace(strUserInput,"-",vbNullString)
response.write strUserInput
%>
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -