PHPÌáÐÑ¿ò£¬°ïæ¿´¿´´úÂë
<?
function func_33df0127f878d1479b493a05ccb4b6aa($params)
{
foreach($params as $key => $value)
{
${$key}= $value;
}
<?php
echo " <script language=\"JavaScript\">alert(\"ÄãºÃ\"); </script>";
?>
}
?>
´ó¼Ò°ïæ¿´¿´ÕâÑùдÓÐûÓÐÎÊÌâ
${$key}= $value;
$$key = $value; ÕâÑù¾Í¿ÉÒÔÁË
Â¥ÉÏÕý½â
²»ÊÇÓÐÏֳɵĺ¯ÊýÂð£¿
extract($params);
Äãͨ¹ý func_33df0127f878d1479b493a05ccb4b6aa ²úÉúµÄ±äÁ¿£¬Ö»ÔÚfunc_33df0127f878d1479b493a05ccb4b6aa º¯ÊýÖÐÓÐЧ
<?php
function func_33df0127f878d1479b493a05ccb4b6aa($params)
{
foreach($params as $key => $value)
{
${$key}= $value;
}
?>
<script type="text/javascript">alert("ÄãºÃ"); </script>;
<?php
}
?>
²»ÖªµÀÄãҪʵÏÖʲôЧ¹û
PHP code:
<?php
function func_33df0127f878d1479b493a05ccb4b6aa($params)
{
foreach($params as $key => $value)
{
${$key}= $value;
}
echo "<script language=JavaScript>alert('ÄãºÃ');</script>"
Ïà¹ØÎÊ´ð£º
<!--¹ºÂòÊýÁ¿-->
<div class='buyinfo'>
<table width='auto'>
<tr>
<td><span>¹ºÂòÊýÁ¿£º</sp ......
ÇëÎÊÏÂÄܲ»ÄÜÔÙwindows϶¨ÆÚÇå¿ÕmysqlÒ»¸ö±íÖеÄÈ«²¿Êý¾Ý£¬ÓÃPHPʵÏÖ£¡
лл¸÷λÁË
¾Í±ÈÈçÒ»¸öÐÇÆÚÇå¿ÕÒ»´Î
±ÈÈçÿ¸öÐÇÆÚÁùÁãµãÇå¿ÕÒ»´Î£¡
ллÁË
¼Æ»®ÈÎÎñ...php....sql...truncate....OK
Äã¾ÍÕâ½ÓÔÚҳà ......
ÎÒÔÚmySqlÖÐÓÐÒ»×ֶοɴæhtml±êÇ©£¬±ÈÈç˵ÀïÃæÓÐa±êÇ©
µ«ÊÇÎÒÊäÈë²éѯÌõ¼þaµÄʱºò²¢²»Ïë²é³öÕâÌõ¼Ç¼£¬Ò²¾ÍÊÇ˵²éѯµÄʱºò²»¿¼ÂDZêÇ©,Ö»¿¼ÂÇÄÚÈÝ¡£
ÇëÎÊ´ó¼ÒÔõÑù½â¾ö£¿
¿ÉÒÔÔÙŪһ¸ö×Ö¶ÎÀ´±£´æ¹ýÂ˱êÇ©ºóµÄÄÚÈÝ¡£ ......
ÒѾÐÞ¸ÄÁË
£¨1£©PHP.iniÖеÄpost_max_size ºÍupload_max_filesize£¬²¢ÇÒ±£Ö¤ÁËǰÕß´óÓÚºóÕß
£¨2£©Windows\System32\inetsvr\MetaBase.xmlÖеÄAspMaxRequestEntityAllowed
ÐÞ¸ÄÍê±Ïºó£¬ÖØÐÂÆô¶¯ÁËIIS·þÎñ£¬²¢ÇÒ¼Æ ......
ÎÒÔÚÍøÕ¾µÄÒýµ¼Ò³ÖÐÌí¼ÓÁË<embed src="ÒôÀÖµØÖ·" autostart="true" loop="true" hidden="true"></embed>
Õâ¾ä»°£¬È»ºóÌø×ªÒ³Ãæºó£¬±³¾°ÒôÀÖ¾ÍûÓÐÁË£¬ÔõôÈÃÕ ......