Methods to prevent cross-site scripting attacks
1. Use spaces to replace special characters %<>{};&+-"'()
2. Use @, specifically, to add the following statement
exec="insertintouser(username,psw,sex,department,phone,email,demo)values('"&username&"','"&psw&"','"&sex&"','"&department&"','"&phone&"','"&email&"','"&email&"','"&@demo&"')"
conn.executeexec
Replace with:
exec="insertintouser(username,psw,sex,department,phone,email,demo)values('@username','@psw','@sex','@department','@phone','@email','@demo')"
conn.executeexec