Index: forgon-core/src/main/java/com/forgon/xss/util/XSSFilterUtil.java =================================================================== diff -u -r26897 -r26905 --- forgon-core/src/main/java/com/forgon/xss/util/XSSFilterUtil.java (.../XSSFilterUtil.java) (revision 26897) +++ forgon-core/src/main/java/com/forgon/xss/util/XSSFilterUtil.java (.../XSSFilterUtil.java) (revision 26905) @@ -81,14 +81,14 @@ } //value = StringFilter.StringFilter(value); } - // 预防SQL盲注 - String[] pattern = { "%", "select", "insert", "delete", "from", + // 预防SQL盲注(有影响到相关功能,先注释) + /*String[] pattern = { "%", "select", "insert", "delete", "from", "count\\(", "drop table", "update", "truncate", "asc\\(", "mid\\(", "char\\(", "xp_cmdshell", "exec", "master", "netlocalgroup administrators", "net user", "or", "and" }; for (int i = 0; i < pattern.length; i++) { value = value.replace(pattern[i].toString(), ""); - } + }*/ return value; }