您的位置:首页 > 其它

防止Cross-site scripting (XSS)

2015-06-09 16:53 417 查看
public String filter(String url) {
String sanitized = url;
sanitized = sanitized.replaceAll("<", "<").replaceAll(">", ">");
sanitized = sanitized.replaceAll("\\(", "(").replaceAll("\\)", ")");
sanitized = sanitized.replaceAll("'", "'");
sanitized = sanitized.replaceAll("eval\\((.*)\\)", "");
sanitized = sanitized.replaceAll("[\\\"\\\'][\\s]*javascript:(.*)[\\\"\\\']", "\"\"");
return sanitized;
}
内容来自用户分享和网络整理,不保证内容的准确性,如有侵权内容,可联系管理员处理 点击这里给我发消息
标签: