CookieÖдæÊý×é[php]
¿ÉÒÔͨ¹ýÐòÁл°Ò»¸öÊý×飬Ȼºó·Åµ½cookieÖÐ
´ÓcookieÖеõ½Öµ£¬È»ºóÔÚ·´ÐòÁл¯£¬×ª»»ÎªÊý×é¡£
$cur_goods_array = unserialize(stripslashes($_COOKIE['shop_cart_info']));
¡¡
¡¡setcookie("shop_cart_info",serialize($cur_goods_array));
Ïà¹ØÎĵµ£º
phpµ÷ÓÃÍⲿ³ÌÐòµÄ·½·¨Ò»°ãÓÃexec,systemµÈ£¬µ«ÕâÑùÖ´ÐеÄʱºò±ØÐëµÈ´ýÍⲿ³ÌÐò½áÊøºó£¬phpÒ³Ãæ²ÅÄܼÌÐøÖ´ÐУ¬·ñÔòÍøÒ³»áÒ»Ö±µÈ´ý¡£
ÈçºÎ¸Ä±äÕâÖÖÇé¿öÄØ£¿
Ê×ÏÈ
ÒªÖªµÀphpµ÷ÓõijÌÐòĬÈ϶¼ÊÇ·ÅÔÚºǫ́ÔËÐе쬼´Ê¹ÊÇ×ÀÃæ³ÌÐòÔÚ×ÀÃæÒ²¿´²»µ½£¬µ½½ø³ÌÁбí²ÅÄÜ¿´µ½
ÕâÊÇÓÉÓÚphpµ÷ÓóÌÐòÊÇͨ¹ýapacheÀ´Íê³ÉµÄ£ ......
<%
rs.pagesize=14
page=cint(Request.QueryString("page"))
if page<1 then
page=1
elseif page>rs.pagecount then
page=rs.pagecount
end if
rs.AbsolutePage=page
IF rs.BOF and rs.eof then
Response.Write("<br><br>±¾Õ¾ÔÝÎÞÈÕÖ¾¼Ç¼£¡£¡<br><br>")
response.end
end if ......
·Ö±ðÏÂÔØÁËphp5.2.10ºÍ5.3.0°æ±¾µÄÔ´Â룬²éÕÒµ½ÀïÃæcall_user_function(ÔÚext/standard/basic_functions.c)µÄ·½·¨¡£
ÔÚ5.2.10°æ±¾Àcall_user_functionÓõÄÊDZê×¼µÄphp º¯ÊýµÄд·¨£¬ÓÃzvalÀàÐÍÀ´´æ´¢½ÓÊյIJÎÊý£¬µ÷ÓÃcall_user_function_exÀ´Ö´ÐÐÓû§µÄ·½·¨¡£Èç¹ûµ÷Óò»³É¹¦Ôò·ÖÎöÊDz»ÊǽÓÊÕµ½µÄ²ÎÊýÀïÓÐʲô´íÎó¡£
µ«Ô ......
ÀýÈ磺
A.php
<?php
$usernane
?>
Òª½«A.phpÖØµÄ$usernaneÖµ´«¸øÁíÍâÒ»¸öÒ³Ãæ£¨B.php£©ÖеÄʵÏÖ·½·¨£º
<meta http-equiv='refresh' content='0;url='B.php£¿user=$username'>
½ÓÊÕ
echo $_GET['user'];
ÕâÑù£¬¾Í¿ÉÒÔÔÚB.phpÖзÃÎÊ$use ......
×÷Õß:samisa
ÒÔÏÂÎÄÖеķÒëÃû³Æ¶ÔÕÕ±í
:
payload: ½»Ì¸ÄÚÈÝ
object: ʵÀý
function: º¯Êý
ʹÓÃ
phpÀ´ÊµÏÖÍøÂç·þÎñ
ʹÓÿò¼Ü£º
WSO2
WSF/PHP
°²×°»·¾³£º
windows
»òÕß
linux
£¨Ñá¶ñÓÚÑÛϼÆËã»úÎÄÕ¼ÐÔÓÎÞÊýÄѶ®µÄ·ÒëÒÔ¼°ÊõÓ´Ë´¦¾¡Á¿Ê¹ÓÿÚÓïÒÔ¼°ººÓï¡££©
WSMessages Àࣺ
ÔÚµ÷ÓÃÍøÂç·þÎñµÄ¹ý³ÌÖУ¬Ðè ......