Mark 5 ans auparavant
Parent
commit
464ffeaad8
1 fichiers modifiés avec 1 ajouts et 1 suppressions
  1. 1 1
      src/main/java/io/renren/common/xss/SQLFilter.java

+ 1 - 1
src/main/java/io/renren/common/xss/SQLFilter.java

36
        str = str.toLowerCase();
36
        str = str.toLowerCase();
37
37
38
        //非法字符
38
        //非法字符
39
        String[] keywords = {"master", "truncate", "insert", "select", "delete", "update", "declare", "alert", "drop"};
39
        String[] keywords = {"master", "truncate", "insert", "select", "delete", "update", "declare", "alter", "drop"};
40
40
41
        //判断是否包含非法字符
41
        //判断是否包含非法字符
42
        for(String keyword : keywords){
42
        for(String keyword : keywords){