sqlescapeexample.java

来自「Spring企业级开发下......电子书籍..............」· Java 代码 · 共 16 行

JAVA
16
字号
package com.baobaotao.escape;

import org.apache.commons.lang.StringEscapeUtils;

public class SqlEscapeExample {
	public static void main(String[] args) {
		String userName = "1' or '1'='1";
		String password = "123456";
        userName = StringEscapeUtils.escapeSql(userName);
        password = StringEscapeUtils.escapeSql(password);
		String sql = "SELECT COUNT(userId) FROM t_user WHERE userName='"
				+ userName + "' AND password ='" + password + "'";
        System.out.println(sql);
	}
}

⌨️ 快捷键说明

复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?