Ewebeditor±à¼Æ÷ǶÈëµ½PHPÍøÒ³ÖÐ
/*
>>> Title : Ewebeditor±à¼Æ÷ǶÈëµ½PHPÍøÒ³ÖÐ
>>> Author: Áõ³¿êÍ
>>> Date : 2009-07-05
>>> EMAIL :
huichengongzi@gmail.com
>>> ×ªÔØÇë×¢Ã÷³ö´¦£¬Ð»Ð»ºÏ×÷£¡
*/
£¨1£©ÔÚ
</head>
֮ǰ¼ÓÉÏÏÂÃæÒ»¶Î´úÂ룺£¨µÃµ½
ewebeditor
Öб༵ÄÄÚÈÝ£©
<script>
function checkForm()
{
document.form1.content
.value
= window.ewebeditor
.getHTML();
************getHTML()
»ñµÃ±à¼ÇøÄÚÈÝ
************
´Ë´¦µÄÃû×Ö
ewebeditor
ÒªÓë
iframe
ÖеÄ
name="ewebeditor"
Ïàͬ
************content.value
Ò²ÒªÓë
content
ÖеÄ
<input >
ÖÐÏà¶ÔÓ¦
}
</script>
£¨2£©ÏÂÃæÒ»¶Î´úÂëÊǰÑ
ewebeditor
ǶÈëµ½ÍøÒ³ÖУº
<tr>
<td
align="right" width="5%" >
ÄÚÈÝ£º
</td>
<td
width="95%">
<input
type="hidden" name="content"
id="content"
value
="">
**********id="content"
ÖеÄ
content
ÒªÓë
<iframe>
ÖеÄ
id=content
Ïàͬ£¡
<iframe id="ewebeditor" name="ewebeditor"
src="ewebeditor/ewebeditor.php?id=content
" frameborder="0"
scrolling="no" width="100%"
Ïà¹ØÎĵµ£º
PHPÕýÔò±í´ïʽÖ÷ÒªÓÃÓÚ×Ö·û´®µÄģʽ·Ö¸î¡¢Æ¥Åä¡¢²éÕÒ¼°Ìæ»»²Ù×÷¡£Ê¹ÓÃÕýÔò±í´ïʽÔÚijЩ¼òµ¥µÄ»·¾³Ï¿ÉÄÜЧÂʲ»¸ß£¬Òò´ËÈçºÎ¸üºÃµÄʹÓÃPHPÕýÔò±í´ïʽÐèÒª×ۺϿ¼ÂÇ¡£
ÎÒµÄPHPÕýÔòÈëÃÅ£¬ÊÇÆðÔ´ÓÚÍøÉϵÄһƪÎÄÕ£¬ÕâÆªÎÄÕÂÓÉdzÈëÉîµÄ²ûÊöÁËPHPÕýÔò±í´ïʽʹÓõķ½·¨£¬ÎÒ¾õµÃÊÇÒ»¸öºÜºÃµÄÈëÃŲÄÁÏ£¬²»¹ýѧ³É»¹ÊÇÒª¿¿¸öÈË£¬ÔÚʹÓà ......
Php×¢Èë¹¥»÷ÊÇÏÖ½ñ×îÁ÷ÐеĹ¥»÷·½Ê½£¬ÒÀ¿¿ËüÇ¿´óµÄÁé»îÐÔÎüÒýÁ˹ã´óºÚÃÔ¡£
ÔÚÉÏÒ»ÆÚµÄ¡¶php°²È«Óë×¢ÉäרÌâ¡·ÖÐÁÖ.linxÖ÷Òª½²ÊöÁËphp³ÌÐòµÄ¸÷ÖÖ©¶´£¬Ò²½²µ½ÁËphp£«mysql×¢ÈëµÄÎÊÌ⣬¿ÉÊǽ²µÄ×¢ÈëµÄÎÊÌâ±È½ÏÉÙ£¬ÈÃÎÒÃǸоõûÓо¡ÐËÊǰÉ.
OK,ÕâÒ»ÆÚÎÒ½«¸ø´ó¼Ò»ï×Ð×ÐϸϸµÄ´µÒ»´µphp£«mysql×¢È룬һ¶¨ÈÃÄãÂúÔØ¶ø¹éŶ ......
¶ÔÓڽű¾°²È«Õâ¸ö»°ÌâºÃÏñÓÀԶûÍêûÁË£¬Èç¹ûÄã¾³£µ½¹úÍâµÄ¸÷ÖÖ¸÷ÑùµÄbugtraqÉÏ£¬Äã»á·¢ÏÖÓÐÒ»°ëÒÔÉ϶¼ºÍ½Å±¾Ïà¹Ø£¬ÖîÈçSQL
injection£¬XSS£¬Path Disclosure£¬Remote commands executionÕâÑùµÄ×ÖÑ۱ȱȽÔÊÇ£¬ÎÒÃÇ¿´ÁËÖ®ºóµÄÓÃ;ÄѵÀ½ö½öÊÇ×¥È⼦?¶ÔÓÚÎÒÃÇÏë×öweb°²È«µÄÈËÀ´Ëµ£¬×îºÃ¾ÍÊÇÄÃÀ´Ñ§Ï°
£¬¿ÉÊÇÍòÎï×¥¸ùÔ´£¬ÎÒà ......
Äã²»±ØÑϸñ×ñÊØÕâЩÔÔò£¬Î¥±³ËüÃÇÒ²²»»á±»´¦ÒÔ×Ú½ÌÐÌ·£¡£µ«ÄãÓ¦µ±°ÑÕâЩÔÔò¿´³É¾¯Á壬ÈôÎ¥±³ÁËÆäÖеÄÒ»Ìõ£¬ÄÇô¾¯Áå¾Í»áÏìÆð ¡£ ----- Arthur J.Riel
(1)ËùÓÐÊý¾Ý¶¼Ó¦¸ÃÒþ²ØÔÚËùÔÚµÄÀàµÄÄÚ²¿¡£
(2)ÀàµÄʹÓÃÕß±ØÐëÒÀÀµÀàµÄ¹²Óнӿڣ¬µ«À಻ÄÜÒÀÀµËüµÄʹÓÃÕß¡£
(3)¾¡Á¿¼õÉÙÀàµÄÐÒéÖÐµÄ ......
ҪʹÄúµÄFCKeditorÄܹ»Ê¹ÓÃÉÏ´«¹¦ÄÜ£¬Äú±ØÐë½øÐÐÒÔÏÂÅäÖÆ¡£
×¢Ò⣺FCKeditor²»Ö§³ÖÐéÄâĿ¼£¬ÄúµÄ·¾¶ÉèÖö¼ÊÇÕë¶ÔÍøÕ¾¸ùĿ¼µÄ¾ø¶Ô·¾¶¶øÑԵġ£Õâµã¶ÔÓÚ·¢²¼µ½Ô¶³ÌÍøÕ¾Ä¿Â¼µÄ¿ª·¢Õß¼«Îª²»±ã£¬ºóÃæÎÒÃÇ»á¶Ô´Ë½øÐÐÌÖÂÛ¡£
Ò»¡¢´ò¿ªfckeditor\editor\filemanager\upload\php\config.php£¬ÕÒµ½´úÂë$Config['Enabled']£¬½«Öµ ......