The PHP coder's top 10 mistakes and problems @ SourceRally.net PHP Community 「PHPプãƒã‚°ãƒ©ãƒžãŒãŠã‹ã—ãŒã¡ãªãƒŸã‚¹ï¼´ï¼¯ï¼°ï¼‘ï¼ã€ã€ã¨ã„ã†è¨˜äº‹ãŒã‚ã£ãŸã®ã§ç´¹ä»‹ã€‚ PHPåˆå¿ƒè€…ã ã¨ã“ã†ã„ã†ãƒŸã‚¹ãŒã‚ˆãã‚ã‚Šã¾ã™ã。ã¨ã„ã†ã“ã¨ã§ä»Šå¹´ã‹ã‚‰PHPã‚’ã¯ã˜ã‚よã†ã¨æ€ã£ã¦ã„る人ã«ã¯æ°—ã‚’ã¤ã‘ã¦ã»ã—ã„リストã§ã™ã€‚ 生ã§ã‚¯ã‚¨ãƒªã‚’出力ã—ãªã„ echo $_GET['username']; ↓ echo htmlspecialchars($_GET['username'], ENT_QUOTES); やらãªã„ã¨ã‚¯ãƒã‚¹ã‚µã‚¤ãƒˆã‚¹ã‚¯ãƒªãƒ—ティングã•ã‚Œã¾ã™ã€‚ SQLクエリã«ï¼„_GET,$_POST,$_REQUESTã®å€¤ã‚’直接å«ã‚ãªã„ $sql = "select * from table where id=".$_GET["id"]; ↓ $sql =
{{#tags}}- {{label}}
{{/tags}}