| | |
| | | value = ESAPI.encoder().canonicalize(value); |
| | | |
| | | // 避免空字符串 |
| | | value = value.replaceAll(" ", ""); |
| | | //value = value.replaceAll(" ", ""); |
| | | |
| | | // 删除 ' |
| | | value = value.replaceAll("'",""); |
| | |
| | | value = scriptPattern.matcher(value).replaceAll(""); |
| | | |
| | | // 避免 onXX= 表达式 |
| | | scriptPattern = compile("on.*(.*?)=", CASE_INSENSITIVE | MULTILINE | DOTALL); |
| | | value = scriptPattern.matcher(value).replaceAll(""); |
| | | /*scriptPattern = compile("on.*(.*?)=", CASE_INSENSITIVE | MULTILINE | DOTALL); |
| | | value = scriptPattern.matcher(value).replaceAll("");*/ |
| | | |
| | | } |
| | | return value; |