dsztc99732 2015-06-03 08:27
浏览 92
已采纳

WordPress SQL注入URL参数

I wrote a very little WordPress application that uses URL parameter values to generate html content on a public site like this:

URL example:

www.mydomain/?prmtr=Chicago

Code:

$prmtr = isset( $_GET['prmtr'] ) ? $_GET['prmtr'] : 'NewYork';

A possible HTML integration is like this

<h1>Hello Person from <?php echo $prmtr; ?></h1>

Is WordPress doing all the "dirty work" for me, like preventing attackers from injecting SQL commands or other stuff?

Thanks in advance, Ben

  • 写回答

1条回答 默认 最新

  • dragon8837 2015-06-03 08:29
    关注

    Nope. That's raw PHP you've got there. You'll have to make it safe yourself.

    As long as all you're doing with $prtmr is printing it out you don't need to worry about SQL injection, just XSS attacks.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 DS18B20内部ADC模数转换器
  • ¥15 做个有关计算的小程序
  • ¥15 MPI读取tif文件无法正常给各进程分配路径
  • ¥15 如何用MATLAB实现以下三个公式(有相互嵌套)
  • ¥30 关于#算法#的问题:运用EViews第九版本进行一系列计量经济学的时间数列数据回归分析预测问题 求各位帮我解答一下
  • ¥15 setInterval 页面闪烁,怎么解决
  • ¥15 如何让企业微信机器人实现消息汇总整合
  • ¥50 关于#ui#的问题:做yolov8的ui界面出现的问题
  • ¥15 如何用Python爬取各高校教师公开的教育和工作经历
  • ¥15 TLE9879QXA40 电机驱动