修改MY_Controller.php
$this->checkUrl();
public function checkUrl() {
$cur_uri = ($_SERVER["REQUEST_URI"] == $_SERVER["PHP_SELF"]) ? $_SERVER["PHP_SELF"] . "?" : $_SERVER["REQUEST_URI"];
$cur_uri=strtolower($cur_uri);
$cur_uri= urldecode($cur_uri);
$filter_array = array('script','iframe','alert',',','#','¥','confirm',';','document','eval','LF','CR','(',')','%','@','$','<','>');
$error_msg='';
foreach($filter_array as $val){
if(strstr($cur_uri,$val)){
die('Disallowed Key Characters.');
return false;
}
}
return true;
}
没有帐号? 立即注册