doucai4274 2016-01-08 14:22
浏览 20
已采纳

Joomla,正确逃离他们自己的组件

I have written a custom component for Joomla. This RSS feed can be read from different sources and should be stored in the SQL database.

But how do I use the escape function properly? Here is my code:

// Create a new query object.
$query = $db->getQuery(true);

// Insert columns.
$columns = array('id',
                 'id_feedsource', 
                 'title', 
                 'link', 
                 'pubDate', 
                 'timePubDate', 
                 'guid', 
                 'description', 
                 'creator', 
                 'content' , 
                 'read', 
                 'smart', 
                 'demografie', 
                 'urbanisierung', 
                 'arbeitswelten', 
                 'konnektivitaet', 
                 'nano', 
                 'femaleshift', 
                 'energie', 
                 'bildung', 
                 'individualisierung', 
                 'public', 
                 'cache');

// Insert values.
$values = array('NULL',
                $db->quote($db->escape($value['source'])),
                $db->quote($db->escape($value['title'])),
                $db->quote($db->escape($value['link'])),
                $db->quote($db->escape($value['pubDate'])),
                $db->quote($value['timePubDate']),
                $db->quote($db->escape($value['guid'])),
                $db->quote($db->escape($value['description'])),
                $db->quote($db->escape($value['creator'])),
                $db->quote($db->escape($value['content'])),
                0,0,0,0,0,0,0,0,0,0,0,0,0);

// Prepare the insert query.
$query
    ->insert($db->quoteName('#__heka_rss_feeds'))
    ->columns($db->quoteName($columns))
    ->values(implode(',', $values));

// Set the query object and execute it.
$db->setQuery($query);
//echo $query->dump().'<br>';
$db->execute();

Now add in individual contributions "\". For example: NASA\'s Fermi Space Telescope sharpens its high-energy vision

When issuing this does not look nice. Because of the escaping SQL Injection is to be used, but it may not yet be correct. What am I doing wrong?

  • 写回答

1条回答 默认 最新

  • douhuan9289 2016-01-12 14:52
    关注

    I believe the $db->quote also escapes the values. So you will have double escapes the way you did it. Try

    $values = array('NULL',
                $db->quote($value['source']),
                $db->quote($value['title']),
                $db->quote($value['link']), 
                ...
    

    ...which should work better. See docs here

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 centos7.9 IPv6端口telnet和端口监控问题
  • ¥120 计算机网络的新校区组网设计
  • ¥20 完全没有学习过GAN,看了CSDN的一篇文章,里面有代码但是完全不知道如何操作
  • ¥15 使用ue5插件narrative时如何切换关卡也保存叙事任务记录
  • ¥20 海浪数据 南海地区海况数据,波浪数据
  • ¥20 软件测试决策法疑问求解答
  • ¥15 win11 23H2删除推荐的项目,支持注册表等
  • ¥15 matlab 用yalmip搭建模型,cplex求解,线性化处理的方法
  • ¥15 qt6.6.3 基于百度云的语音识别 不会改
  • ¥15 关于#目标检测#的问题:大概就是类似后台自动检测某下架商品的库存,在他监测到该商品上架并且可以购买的瞬间点击立即购买下单