douweng7308 2014-10-12 17:29
浏览 37
已采纳

清理select,radio,checkbox中的值?

Does a select input (or a checkbox or a radio) need to be sanitized and / or escaped, assuming that the value will be used in a query? And if yes, why? I mean, how that value could be altered by someone?

  • 写回答

2条回答 默认 最新

  • doupo1908 2014-10-12 17:32
    关注

    Yes, you should always sanitize all input. Just because you're giving the user a choice from a select, radio, or checkbox, doesn't mean they can't use the web inspector to change the values they can choose from. Also, they can always manufacture their own GET or POST request to send whatever values they want.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论
查看更多回答(1条)

报告相同问题?

悬赏问题

  • ¥15 我想咨询一下路面纹理三维点云数据处理的一些问题,上传的坐标文件里是怎么对无序点进行编号的,以及xy坐标在处理的时候是进行整体模型分片处理的吗
  • ¥15 CSAPPattacklab
  • ¥15 一直显示正在等待HID—ISP
  • ¥15 Python turtle 画图
  • ¥15 关于大棚监测的pcb板设计
  • ¥15 stm32开发clion时遇到的编译问题
  • ¥15 lna设计 源简并电感型共源放大器
  • ¥15 如何用Labview在myRIO上做LCD显示?(语言-开发语言)
  • ¥15 Vue3地图和异步函数使用
  • ¥15 C++ yoloV5改写遇到的问题