gbk双字节注入

//连接数据库部分,注意使用了gbk编码
$conn = mysql_connect('localhost', 'root', 'toor!@#$') or die('bad!');
mysql_query("SET NAMES 'gbk'");
mysql_select_db('test', $conn) OR emMsg("连接数据库失败,未找到您填写的数据库");
//执行sql语句
$id = isset($_GET['id']) ? addslashes($_GET['id']) : 1;
$sql = "SELECT * FROM news WHERE tid='{$id}'";
$result = mysql_query($sql, $conn) or die(mysql_error());
?>
新闻
$row = mysql_fetch_array($result, MYSQL_ASSOC);
echo "

{$row['title']}

{$row['content']}

\n";

mysql_free_result($result);
?>
 
 
救赎之道:
if($this->server_info() > ‘4.1′){
//mysql_query(“SET NAMES ‘gbk’”);
mysql_query(“SET character_set_connection=’gbk’,character_set_results=’gbk’,character_set_client=binary”);
}

你可能感兴趣的:(gbk双字节注入)