; $email=$aFormValues[''email'']; $pwd=$aFormValues[''pwd'']; $pw=Md5($pwd); $errmsg=""; //要过滤的非法字符 $ArrFiltrate=array("''",";","union");
foreach($aFormValues as $key=>$value){ if (FunStringExist($value,$ArrFiltrate)){ $objResponse->addAlert("输入的信息含有非法字符\"'' ; union!\""); $objResponse->addAssign("submitButton","value","继续"); $objResponse->addAssign("submitButton","disabled",false); return $objResponse; } } if (trim($usr) == "") { $errmsg.="请输入用户名!\n"; } if (trim($pwd) == "") { $errmsg.="请输入密码!\n"; } if ($pwd != $aFormValues[''pwd2'']) { $errmsg.="两次输入的密码不一致!\n"; } if (!CheckEmailAddr($email)) { $errmsg.="邮件地址不正确!\n"; } $sql="select * from zl_usr where zl_usr=''$usr''"; $result=mysql_query($sql,$db); if($myrow=mysql_fetch_array($result)){ $errmsg.="用户名已经存在!\n"; } if ($errmsg=="") { $sForm = "注册成功<br>用户名:".$usr."<br>email:".$email.""; $sql="insert into zl_usr(zl_usr,zl_pwd,email) values(''$usr'',''$pw'',''$email'')"; $result=mysql_query($sql,$db); $objResponse->addAssign("formDiv","innerHTML",$sForm); } else { $objResponse->addAlert($errmsg); //弹出错误信息 $objResponse->addAssign("submitButton","val |