- 论坛徽章:
- 0
|
在网上看到的PHPBB里的代码~
- if ( isset($HTTP_POST_VARS['folder']) || isset($HTTP_GET_VARS['folder']) )
- {
- $folder = ( isset($HTTP_POST_VARS['folder']) ) ? $HTTP_POST_VARS['folder'] : $HTTP_GET_VARS['folder'];
- $folder = htmlspecialchars($folder);
- if ( $folder != 'inbox' && $folder != 'outbox' && $folder != 'sentbox' && $folder != 'savebox' )
- {
- $folder = 'inbox';
- }
- }
- else
- {
- $folder = 'inbox';
- }
复制代码
提交:http://localhost/phpBB2/privmsg.php?folder[]=
回显:
Warning: htmlspecialchars() expects parameter 1 to be string, array given in /www/phpbb2/privmsg.php on line 61
挺有意思的,做下is_string判断就好了 |
|