StringEscapeUtils类的转义与反转义方法

没啥可说的,防止SQL注入

String userName = ”1' or '1'='1”;
    String password = ”123456”;
    userName = StringEscapeUtils.escapeSql(userName);
    password = StringEscapeUtils.escapeSql(password);


http://www.cnblogs.com/anuoruibo/archive/2012/06/14/2549294.html

你可能感兴趣的:(StringEscapeUtils类的转义与反转义方法)