防XSS处理
``
php
echo htmlspecialchars($row['content'], ENT_QUOTES, 'UTF-8');
`
数据插入
`php
$sql = "INSERT INTO messages (name, content) VALUES (?, ?)";
$stmt = $db->prepare($sql);
$stmt->execute([$name, $msg]);
`` php
echo htmlspecialchars($row['content'], ENT_QUOTES, 'UTF-8');
`
数据插入
`php
$sql = "INSERT INTO messages (name, content) VALUES (?, ?)";
$stmt = $db->prepare($sql);
$stmt->execute([$name, $msg]);
``