phpһЩ»ù´¡µÄÎÊÌâ - PHP / »ù´¡±à³Ì
¸Õ½Ó´¥php£¬Óм¸¸öµØ·½¸Ð¾õºÜ²»Çå³þ 1.±ÈÈçÓиöĿ¼ http://192.168.0.2/www/index.php Ò»°ã´«µÝ²ÎÊýÓ¦¸ÃÏñÕâÑù http://192.168.0.2/www/index.php?var=val, Èç¹ûindex.phpĬÈϵĻ°Ó¦¸Ã¿ÉÒÔд³É http://192.168.0.2/www/?var=val£¬ µ«ÎÒ¿´µ½µÄÊÇ http://192.168.0.2/www/?val ÕâÖÖÑùʽµÄ£¬why£¿ÈçºÎ»ñÈ¡ÄØ£¿£¨²»È·¶¨valÊDz»ÊÇÖµ£¬Ö»ÊǸоõÓ¦¸ÃÊÇ£© 2.ÉÏÃæµÄindex.phpÄÚÈÝÊÇ PHP code: header("location:./abc/index.php"); exit(); Õâ¸öÓ¦¸ÃÊÇÌøתµ½abcĿ¼µÄindex.phpÁË£¬¸Õ²Åhttp://192.168.0.2/www/?val ÖУ¬valÒ²´«¹ýÈ¥ÁË£¿ ·¿´Ò»ÏÂwww/abc/index.php£¬·¢ÏÖ$_SCONFIG¡¢$_SGETÕâÑùµÄ±äÁ¿£¬ÊÇϵͳ±äÁ¿Ã´£¿ ÈçºÎÇø·ÖÊÇ×Ô¶¨Ò廹ÊÇϵͳµÄ£¿£¨ÓüÇʱ¾¿´µÄ£¬Ò²Ã»ÑÕÉ«Ìáʾ£© ÎÊÌâÓеãÂÞ࣬²»¹ý¸Õ½Ó´¥phpȷʵÓеãÔΣ¬Íû¸÷λǰ±²Ö¸½Ì
²¹³ä¸öÎÊÌ⣺ 3. $_GET["id"],Èç¹ûûÓд«¹ýÀ´»áÌáʾ Undefined index: id£¬Õâ¸öÔõô½â¾ö£¿¾ÍÊÇû´©¹ýÀ´¾ÍÊÇֵΪ¡°¡±¾ÍÊÇÁË£¿ ÎÊÌâ1:ºÃÏñÊÇ$_SERVER["QUERY_STRING"]£¿ÕâÑùдÓÐɶºÃµÄ¡£¡£ÒýÓà 1¡¢Ö»Óмü£¬Ã»ÓÐÖµ¡£¹ãÒåµÄ˵£¬¼üÒ²ÊÇÖµ Õâ»°²»Ì«Ã÷°×£¬ÊÇ˵¡°var=val¡±±¾Éí¿ÉÒÔËãÒ»¸öÖµ£¿¾Í¿´ÎÒÔõô¿´ÁË£¿ ÆäËû»Ø´ðµÄͦÇå³þ¡£Ë¬¿ì
Ïà¹ØÎÊ´ð£º
Ä¿Ç°ÔÚÎ人ÕÒ¹¤×÷ ·¢Ïִ󲿷ֹ«Ë¾ÎÞÍâºõÁ½ÖÖ Ò»ÖÖÊǸãÍâ°üµÄ ÒªÓÃzend,cakephpµÈÍâ¹ú¿ò¼Ü »¹ÒªÊìϤÍâ¹ú¿ªÔ´ÏµÍ³ Ò»ÖÖ¹úÄÚµÄ ÎÞÍâºõ dedecms ecshop shopexÕ⼸ÖÖ¸ÄÕ¾µã ÓеĹ«Ë¾ÉõÖÁÄÃһЩ¸üСµÄϵͳ¸ ......
mssql_select_db("f1",mssql_connect("localhost","sa","sa")); mssql_select_db("f2",mssql_connect("192.168.0.1","sa","sa") ......
1¡¢ÊDz»ÊÇPHPÖÐÖ»ÄÜʹÓÃmysql_query("update user_aa set money=money2-".$bpanmm." where uid=".$userppp);¸üÐÂÊý¾Ý£¿£¿£¿ 2¡¢PHP¸üÐÂmysql_fetch_row($res)Óëmysql_fetch_array($res)ÖеÄÊý¾ ......
ÈçÌ⣬Ôõôд¸öheadÍ·²¿ ÈÃÒ³Ã滺´æ1ÐÇÆÚ¡£ header("Expires: Mon, 26 Jul 1997 05:00:00 GMT"); Äã°ÑÀïÃæµÄʱ¼ä£¬¸Ä³Éµ±Ç°Ê±¼ä¼ÓÉÏÒ»¸öÐÇÆÚ ¼ÇµÃҪת»»³Égmtʱ¼ä ÎÒÕâÑùдµÄ ²»ÖªµÀÐв»ÐС£ Ò»¸öÐ ......
ÏÖÔÚÓÐa,bÈý¸öÒ³Ãæ bÊǵǽҳÃ棬·ÃÎÊaÒ³Ã棬Èç¹ûûÓеǼ£¬Ôòheaderµ½bÒ³Ãæ ÔÚbÒ³ÃæÈ¡²»µ½HTTP_REFERER òËÆHTTP_REFERERÖ»ÄÜÈ¡µ½a±êÇ©ºÍpost,get·½·¨µÄÌøת Äܲ»ÄÜαÔìÒ»¸öHTTP_REFERER£¬È»ºó¹ýÈ¥£¿ ¼ÈÈ»Ö ......