1.  $str=preg_replace("/\s+/"" "$str); //过滤多余回车 
  2. $str=preg_replace("/<[ ]+/si","<",$str); //过滤<__("<"号后面带空格) 
  3.     
  4. $str=preg_replace("/<\!--.*?-->/si","",$str); //注释 
  5. $str=preg_replace("/<(\!.*?)>/si","",$str); //过滤DOCTYPE 
  6. $str=preg_replace("/<(\/?html.*?)>/si","",$str); //过滤html标签 
  7. $str=preg_replace("/(?=href=)([^\>]*)(?=\>)/i","",$str); //过滤a标签 
  8. $str=preg_replace("/<(\/?head.*?)>/si","",$str); //过滤head标签 
  9. $str=preg_replace("/<(\/?meta.*?)>/si","",$str); //过滤meta标签 
  10. $str=preg_replace("/<(\/?body.*?)>/si","",$str); //过滤body标签 
  11. $str=preg_replace("/<(\/?link.*?)>/si","",$str); //过滤link标签 
  12. $str=preg_replace("/<(\/?form.*?)>/si","",$str); //过滤form标签 
  13. $str=preg_replace("/cookie/si","COOKIE",$str); //过滤COOKIE标签 
  14.     
  15. $str=preg_replace("/<(applet.*?)>(.*?)<(\/applet.*?)>/si","",$str); //过滤applet标签 
  16. $str=preg_replace("/<(\/?applet.*?)>/si","",$str); //过滤applet标签 
  17.     
  18. $str=preg_replace("/<(style.*?)>(.*?)<(\/style.*?)>/si","",$str); //过滤style标签 
  19. $str=preg_replace("/<(\/?style.*?)>/si","",$str); //过滤style标签 
  20.     
  21. $str=preg_replace("/<(title.*?)>(.*?)<(\/title.*?)>/si","",$str); //过滤title标签 
  22. $str=preg_replace("/<(\/?title.*?)>/si","",$str); //过滤title标签 
  23.     
  24. $str=preg_replace("/<(object.*?)>(.*?)<(\/object.*?)>/si","",$str); //过滤object标签 
  25. $str=preg_replace("/<(\/?objec.*?)>/si","",$str); //过滤object标签 
  26.     
  27. $str=preg_replace("/<(noframes.*?)>(.*?)<(\/noframes.*?)>/si","",$str); //过滤noframes标签 
  28. $str=preg_replace("/<(\/?noframes.*?)>/si","",$str); //过滤noframes标签 
  29.     
  30. $str=preg_replace("/<(i?frame.*?)>(.*?)<(\/i?frame.*?)>/si","",$str); //过滤frame标签 
  31. $str=preg_replace("/<(\/?i?frame.*?)>/si","",$str); //过滤frame标签 
  32.     
  33. $str=preg_replace("/<(script.*?)>(.*?)<(\/script.*?)>/si","",$str); //过滤script标签 
  34. $str=preg_replace("/<(\/?script.*?)>/si","",$str); //过滤script标签 
  35. $str=preg_replace("/javascript/si","Javascript",$str); //过滤script标签 
  36. $str=preg_replace("/vbscript/si","Vbscript",$str); //过滤script标签 
  37. $str=preg_replace("/on([a-z]+)\s*=/si","On\\1=",$str); //过滤script标签 
  38. $str=preg_replace("/&#/si","&#",$str); //过滤script标签,如alert()< /span>