Check the input content, if the sensitive characters are included, delete sensitive characters include: '> <=! - * / () |; and space, then patch up the SQL statement If you are patching, then filter, the workload is big, and Too many side effects