; *</td> </tr> <tr> <td align="right">密码:</td> <td><input name="pwd" type="password" id="pwd" /> *</td> </tr>
<tr align="center"> <td colspan="2"><input type="submit" name="submitButton" value="提交" class="button" /> <input type="reset" name="Submit2" value="重置" class="button" /></td> </tr> </table> </div> </div> </form> </body> </html>
4、inc/login.php 登陆用的处理文件
<?php define (''XAJAX_DEFAULT_CHAR_ENCODING'', ''gb2312'' ); require_once("xajax.inc.php"); require_once("function.php"); $xajax = new xajax(); $xajax->registerFunction("processForm"); function processForm($aFormValues) { $objResponse = new xajaxResponse(); require_once("conn.php"); $usr=$aFormValues[''usr'']; $email=$aFormValues[''email'']; $pwd=$aFormValues[''pwd'']; $pw=Md5($pwd); $errmsg=""; //要过滤的非法字符 $ArrFiltrate=array("''",";","union");
foreach($aFormValues as $key=>$value){ if (FunStringExist($value,$ArrFiltrate)){ $objResponse->addAlert("输入的信息含有非法字符\"'' ; union!\""); $objResponse->addAssign("submitButton","value","继续"); $objResponse->addAssign("submitButton","disabled",false); return $objResponse; } } if (trim($usr) == "") { $errmsg.="请输入用户名!\n"; } if (trim($pwd) == "") { $errmsg.="请输入密码!\n"; } $sql="select * from zl_usr where zl_usr=''$usr'' and zl_pwd=''$pw''"; |