PHP ѹËõÎļþ¼ÐµÄÀ࣡
<?php
/*
$Id: PHPZip.php
*/
class PHPZip {
var $datasec = array();
var $ctrl_dir = array();
var $eof_ctrl_dir = "\x50\x4b\x05\x06\x00\x00\x00\x00";
var $old_offset = 0;
function Zip($dir, $zipfilename) {
if (@function_exists('gzcompress')) {
@set_time_limit("0");
$this->openFile($dir,$dir);
$out = $this -> filezip();
$fp = fopen($zipfilename, "w");
fwrite($fp, $out, strlen($out));
fclose($fp);
}
}
function openFile($path, $zipName) {
$temp_path = $path;
$temp_zip_path = $zipName;
$zipDir = $zipName;
if ($handle = @opendir($path)) {
while (false !== ($file = readdir($handle))) {
if($file !='.' and $file !='..'){
if(ereg('\.' , $file.@basename())) {
$fd = fopen($path.'/'.$file, "r");
$fileValue = @fread ($fd, 1024000);
fclose ($fd);
$this -> addFile($fileValue, $zipName . '/' . $file);
} else {
$this ->openFile($path.'/'.$file, $zipName . '/' . $file);
}
&nbs
Ïà¹ØÎĵµ£º
ÓÃPHP¹ýÂËÌá½»±íµ¥µÄhtml´úÂëÀï¿ÉÄÜÓб»ÀûÓÃÒýÈëÍⲿΣÏÕÄÚÈݵĴúÂë¡£ÀýÈ磬ÓÐЩʱºòÓû§Ìá½»±íµ¥Öк¬ÓÐhtmlÄÚÈÝ£¬µ«Õâ¿ÉÄÜÔì³ÉÏÔʾҳÃæ²¼¾Ö»ìÂÒ£¬ÐèÒª¹ýÂ˵ô¡£
ÒÔÏÂÊdzÌÐò´úÂ룺
¸´ÖÆ´úÂë
function uhtml($str)
{
$farr = array(
......
1¡¢mysql_connect()-½¨Á¢Êý¾Ý¿âÁ¬½Ó {3RY4HVT?
¸ñʽ£º Fv n:V\eb
resource mysql_connect([string hostname [:port] [:/path/to/socket] [, string username] [, string password]]) _I;+p eq
Àý£º 1(V>8}zn
$conn = @mysql_connect("localhost", "username", "password") or dir(" ......
˵Ã÷£ºÒòΪ×î½ü¹¤×÷¹¤×÷¹Øϵ£¬ÐèÒª¿ª·¢Ò»¸öÔÚLinuxÏÂÔËÐеÄWeb Application£¬ÐèÒª¶ÔÏÖÔڱȽÏÁ÷ÐеÄһЩPHP¿ò¼Ü×öÒ»¸öÁ˽âºÍÆÀ¹À£¬ÏÂÃæµÄÕâƪÎÄÕÂÊDZÊÕß×î½üѧϰһ¸ö±È½ÏеÄPHP FrameworkµÄÒ»µã¾ÀúºÍ²Ù×÷²½Ö裬ÒòΪ¹Ù·½µÄÊÖ²áдµÃ±È½Ï»Þɬ£¨ÌرðÊÇÖÐÎĵģ©£¬Ôø¾³¢ÊÔ±é¶ÁËüÄǸöÊÖ²áÔÙ¶¯ÊÖ£¬¶ÁÁËÒ»´ó°ë·¢ÏÖÈÔÎÞ·¨Àí½â£¬ÓÚÊÇ ......
global¶¨ÒåÒ»¸öÈ«¾Ö±äÁ¿£¬Õâ¸öÈ«¾Ö±äÁ¿²»ÊÇÓ¦ÓÃÕû¸öÍøÕ¾£¬¶øÊÇÓ¦ÓÃÓ뵱ǰҳÃ棨°üÀ¨requireºÍincludeÎļþ£©Îļþ¡£
$aa="test";
function test()
{
global $aa;
echo $aa;
}
test(); //print test
º¯ÊýÄÚ¶¨ÒåµÄ±äÁ¿º¯ÊýÍâ¿ÉÒÔµ÷Óã¬ÔÚº¯ÊýÍⶨÒåµÄµÄ±äÁ¿º¯ÊýÄÚ²»ÄÜʹÓá£
gl ......
1¡¢$_SERVER['SCRIPT_NAME']¡¢$_SERVER['PHP_SELF']ºÍ$_SERVER['REQUEST_URI']Çø±ð
Àý×Ó:http://localhost/phpwind75/test.php/%22%3E%3Cscript%3Ealert(’xss’)%3C/script%3E%3Cfoo
$_SERVER['SCRIPT_NAME']Ö»»ñÈ¡½Å±¾Ãû£¬²»»ñÈ¡²ÎÊý,Êä³ö½á¹ûΪ:test.php;
$_SERVER['PHP_SELF']»ñÈ¡½Å±¾Ãûºó£¬Í¬Ê±»ñÈ ......