English 中文(简体)
保证在<textarea>上添加_POST[文本]美元的价值。 只使用PHP的超文本标签
原标题:Secure inserting value of $_POST[ textarea ] into <textarea> HTML tag using PHP only

Is there any way to insert $_POST[ textarea ] into <textarea> without escaping shell special chars? I do sth. like :

 <textarea>
     <?php 
           echo escapeshellcmd($_POST[ textarea_field ]) ; 
     ?>
 </textarea>  

并且我对<代码> chars有问题。 我没有在<代码><textarea>上赢得这些选票,但没有<代码>代谢(>);功能可以张贴<超文本编码>&t;/textarea> tag,并在后面插入从超文本到javascript代码。 请让我就这一问题提出一些建议? Can 在<条码>无<>条码>的<>条码>中插入数据?

事先感谢任何建议。

最佳回答

Try it with htmlspecialchars. einskishellcmd is for a different purpose,即: escaping Shell presss.

问题回答

您是否尝试了 htmlentities , 尚未完成?





相关问题
CSS working only in Firefox

I am trying to create a search text-field like on the Apple website. The HTML looks like this: <div class="frm-search"> <div> <input class="btn" type="image" src="http://www....

image changed but appears the same in browser

I m writing a php script to crop an image. The script overwrites the old image with the new one, but when I reload the page (which is supposed to pickup the new image) I still see the old one. ...

Firefox background image horizontal centering oddity

I am building some basic HTML code for a CMS. One of the page-related options in the CMS is "background image" and "stretch page width / height to background image width / height." so that with large ...

Separator line in ASP.NET

I d like to add a simple separator line in an aspx web form. Does anyone know how? It sounds easy enough, but still I can t manage to find how to do it.. 10x!

热门标签