public static String filParam(String param) {
if (param== null) {
param= "";
}else {
param= param.replaceAll("<", "<").replaceAll(">", ">");
param= param.replaceAll("\\(", "(").replaceAll("\\)", ")");
param= param.replaceAll("'", "");
param= param.replaceAll("eval\\((.*)\\)", "");
param= param.replaceAll("[\\\" \\'][\\s]*javascript:(.*)[\\\"\\']", "\"\"");
param= param.replaceAll("script", "");
param= StringUtil.patternString(param,"insert( \\s+)");
param= StringUtil.patternString(param,"delete( \\s+)");
param= StringUtil.patternString(param,"update( \\s+)");
param= StringUtil.patternString(param,"select( \\s+)");
param= StringUtil.patternString(param,"create( \\s+)");
param= StringUtil.patternString(param,"alter( \\s+)");
param= StringUtil.patternString(param,"drop( \\s+)");
}
return param;
}
if (param== null) {
param= "";
}else {
param= param.replaceAll("<", "<").replaceAll(">", ">");
param= param.replaceAll("\\(", "(").replaceAll("\\)", ")");
param= param.replaceAll("'", "");
param= param.replaceAll("eval\\((.*)\\)", "");
param= param.replaceAll("[\\\" \\'][\\s]*javascript:(.*)[\\\"\\']", "\"\"");
param= param.replaceAll("script", "");
param= StringUtil.patternString(param,"insert( \\s+)");
param= StringUtil.patternString(param,"delete( \\s+)");
param= StringUtil.patternString(param,"update( \\s+)");
param= StringUtil.patternString(param,"select( \\s+)");
param= StringUtil.patternString(param,"create( \\s+)");
param= StringUtil.patternString(param,"alter( \\s+)");
param= StringUtil.patternString(param,"drop( \\s+)");
}
return param;
}