1.strip_tags(剝去字符串中的 HTML 標籤)javascript
strip_tags() 函數剝去字符串中的 HTML、XML 以及 PHP 的標籤。html
2.字符串替換java
str_replace(array(" "," ","\t","\r\n","\r","\n"),array("","","","","","")正則表達式
3.利用正則表達式(效率稍微低一些)cookie
$str=preg_replace("/\s+/", " ", $str); //過濾多餘回車
$str=preg_replace("/<[ ]+/si","<",$str); //過濾<__("<"號後面帶空格)
$str=preg_replace("/<\!--.*?-->/si","",$str); //註釋
$str=preg_replace("/<(\!.*?)>/si","",$str); //過濾DOCTYPE
$str=preg_replace("/<(\/?html.*?)>/si","",$str); //過濾html標籤
$str=preg_replace("/<(\/?head.*?)>/si","",$str); //過濾head標籤
$str=preg_replace("/<(\/?meta.*?)>/si","",$str); //過濾meta標籤
$str=preg_replace("/<(\/?body.*?)>/si","",$str); //過濾body標籤
$str=preg_replace("/<(\/?link.*?)>/si","",$str); //過濾link標籤
$str=preg_replace("/<(\/?form.*?)>/si","",$str); //過濾form標籤
$str=preg_replace("/cookie/si","COOKIE",$str); //過濾COOKIE標籤
$str=preg_replace("/<(applet.*?)>(.*?)<(\/applet.*?)>/si","",$str); //過濾applet標籤
$str=preg_replace("/<(\/?applet.*?)>/si","",$str); //過濾applet標籤
$str=preg_replace("/<(style.*?)>(.*?)<(\/style.*?)>/si","",$str); //過濾style標籤
$str=preg_replace("/<(\/?style.*?)>/si","",$str); //過濾style標籤
$str=preg_replace("/<(title.*?)>(.*?)<(\/title.*?)>/si","",$str); //過濾title標籤
$str=preg_replace("/<(\/?title.*?)>/si","",$str); //過濾title標籤
$str=preg_replace("/<(object.*?)>(.*?)<(\/object.*?)>/si","",$str); //過濾object標籤
$str=preg_replace("/<(\/?objec.*?)>/si","",$str); //過濾object標籤
$str=preg_replace("/<(noframes.*?)>(.*?)<(\/noframes.*?)>/si","",$str); //過濾noframes標籤
$str=preg_replace("/<(\/?noframes.*?)>/si","",$str); //過濾noframes標籤
$str=preg_replace("/<(i?frame.*?)>(.*?)<(\/i?frame.*?)>/si","",$str); //過濾frame標籤
$str=preg_replace("/<(\/?i?frame.*?)>/si","",$str); //過濾frame標籤
$str=preg_replace("/<(script.*?)>(.*?)<(\/script.*?)>/si","",$str); //過濾script標籤
$str=preg_replace("/<(\/?script.*?)>/si","",$str); //過濾script標籤
$str=preg_replace("/javascript/si","Javascript",$str); //過濾script標籤
$str=preg_replace("/vbscript/si","Vbscript",$str); //過濾script標籤
$str=preg_replace("/on([a-z]+)\s*=/si","On\\1=",$str); //過濾script標籤
$str=preg_replace("/&#/si","&#",$str); //過濾script標籤,如javAsCript:alert(app