("#eval#i", 'eval', $str);
$str = preg_replace("#union#i", 'union', $str);
$str = preg_replace...("#concat#i", 'concat', $str);
$str = preg_replace("#--#", '--', $str);
$str = preg_replace("...>/','',$text);
//完全过滤js
$text = preg_replace('/<script?..../过滤危险的属性,如:过滤on事件lang js
while(preg_match('/(<
+)(lang|on|action|background|codebase|dynsrc...|javascript:|js:|about:|file:|document.