浏览代码

防止sql注入

visuddhinanda 4 年之前
父节点
当前提交
5ff4e5509b
共有 1 个文件被更改,包括 2 次插入2 次删除
  1. 2 2
      app/pcdl/get_res_index.php

+ 2 - 2
app/pcdl/get_res_index.php

@@ -12,7 +12,7 @@ if (isset($_COOKIE["language"])) {
 require_once "language/db_{$lang}.php";
 require_once "language/db_{$lang}.php";
 
 
 if (isset($_GET["book"])) {
 if (isset($_GET["book"])) {
-    $book = $_GET["book"];
+    $book = (int)$_GET["book"];
 } else {
 } else {
     echo "no book id";
     echo "no book id";
     exit;
     exit;
@@ -28,7 +28,7 @@ if (isset($_GET["album"])) {
 }
 }
 
 
 if (isset($_GET["paragraph"])) {
 if (isset($_GET["paragraph"])) {
-    $paragraph = $_GET["paragraph"];
+    $paragraph = (int)$_GET["paragraph"];
 } else {
 } else {
     $paragraph = -1;
     $paragraph = -1;
 }
 }