/**
* 处理字符转义
*
* @param value
* @return
*/
private String valueClear(String value) {
if (value == null || "".equals(value)) {
return value;
}
String result = value.toLowerCase()
.replaceAll("(^|\\&)|(\\|)|(\\;)|(\\$)|(\\%)|(\\@)|(\\')|(\\\")|(\\>)|(\\<)|(\\))|(\\()|(\\+)|(\\,)|(\\\\)|(\\#|$)|(\\*)|(\\?)|(\\!)|(\\_)|(\\=)|(\\^)|(\\~)","")
.replaceAll("and", "")
.replaceAll("exec", "")
.replaceAll("insert", "")
.replaceAll("select", "")
.replaceAll("delete", "")
.replaceAll("update", "")
.replaceAll("count", "")
.replaceAll("chr", "")
.replaceAll("mid", "")
.replaceAll("master", "")
.replaceAll("truncate", "")
.replaceAll("char", "")
.replaceAll("declare", "")
.replaceAll("or", "")
.replaceAll("mid", "")
.replaceAll("set", "")
.replaceAll("from", "");
return result;
}
防sql注入简单通用方法
最新推荐文章于 2023-06-29 11:52:41 发布