¹ØÓÚphpÀïµÄinclude
ÔÚÒÔǰµÄ×öµÄÀý×ÓÖÐÓöµ½¹ýÖØ¸´µÄ¼ÓÔØµÄ´íÎó ¶î ÄǸöÊÇͨ¹ýinclude_once()À´½â¾ö »òÕß²»ÈÃËûÖØ¸´¼ÓÔØ°ÑÖØ¸´µÄinclude()È¥µôÒ»¸ö»ò¶à¸ö£¬×îÖÕֻʣÏÂÒ»¸öÕâÑùÎÊÌâ¾Í½â¾öÁË£¬µ«½ñÌìÓöµ½µÄÎÊÌâ¾Í¼¬ÊÖÁË ËµÊÇÕÒ²»µ½Îļþ¡£
ÊÂÇéÊÇÕâÑùµÄ £¬½ñÌìÔÚÎļþ¼ÐÀïÔÙн¨ÁËÒ»¸öÎļþ¼Ð£¬È»ºóÒÔǰincludeµÄÎļþ¾Í³ö»ÆÏßÁË£¬È»ºóÔÚÇ°ÃæÔÙ¼ÓÁË../»ÆÏßÏûʧ£¬²»¹ýеÄÎÊÌâ³öÏÖÁË£¡
¼ÙÉèÎÒµÄproject¹¤³ÌÀïµÄclassÎļþÓÐÕâôһ¸öclass.php¶øÆäÖÐÓÖinclude£¨../dao/userdao.php£©,¶øuserdao.phpÀïinclude(../db/db_connect.php)È»ºóÎÒÔÚclassÎļþ¼ÐÓÖн¨ÁËÒ»¸öuserÎļþ¼ÐÈ»ºó°Ñclass.php·Å½øuserÀïÍ·£¬»ÆÏß³öÏ־ͰÑclass.phpÀïµÄinclude¸Ä³Éinclude(../../dao/userdao.php),ÕýÈçÉ϶ÎËù˵£¬»ÆÏßÏûʧ£¬ÕâÏÂÌáʾ˵ÕÒ²»µ½db_connect.php ,ÎÊÌ⻹ûÓнâ¾ö£¬ÄѵÀÎҵðÑuserÎļþɾµô ÔÚproject½¨Ò»¸öuserÎļþ¼Ð£¬ÕâÑùÓ¦¸Ã»áºÃʹ£¬µ«ÓÐûÓиüºÃµÄ°ì·¨£¿»¹ÇëÖªÕ߸æËßÎÒÕâÊÇΪʲô£¬Èç¹ûÄܽ²ÏÂincludeµÄÊÇÔõô¼ÓÔØµÄ£¬¾Í¸üºÃÁË£¬¸Ð¼¤²»¾¡£¬µÈ´ýÎÊÌâµÄ½â¾ö
Ïà¹ØÎĵµ£º
1¡¢$_SERVER['SCRIPT_NAME']¡¢$_SERVER['PHP_SELF']ºÍ$_SERVER['REQUEST_URI']Çø±ð
Àý×Ó:http://localhost/phpwind75/test.php/%22%3E%3Cscript%3Ealert(’xss’)%3C/script%3E%3Cfoo
$_SERVER['SCRIPT_NAME']Ö»»ñÈ¡½Å±¾Ãû£¬²»»ñÈ¡²ÎÊý,Êä³ö½á¹ûΪ:test.php;
$_SERVER['PHP_SELF']»ñÈ¡½Å±¾Ãûºó£¬Í¬Ê±»ñÈ ......
<?php
/*
$Id: PHPZip.php
*/
class PHPZip {
var $datasec = array();
var $ctrl_dir = array();
var $eof_ctrl_dir = "\x50\x4b\x05\x06\x00\x00\x00\x00";
var $old_offset = 0;
& ......
±¾Ì×ÊÓÆµ½Ì³ÌΪ¸ßÇåÊÓÆµ½Ì³Ì£¡ÇëÈ«ÆÁ¹Û¿´£¡±¾Ì×ÊÓÆµ½Ì³Ì½²µÄ±È½Ï¼òµ¥£¬Ö÷Òª½²ÁËApache·þÎñÆ÷µÄÏÂÔØºÍ°²×°£¬mysqlÊý¾Ý¿âµÄ¼òµ¥²Ù×÷µÈµÈ£¬»¹½²ÁËÁÄÌìÊÒÉè¼Æ
,ÁôÑÔ°å,»áÔ±¹ÜÀíϵͳ,ͶƱ¹ÜÀíϵͳ,ͼÊé¹ÜÀíϵͳ,²úÆ·½øÏú´æ¹ÜÀíϵͳ¼¸¸öʵÀý£¬¶¼±È½Ï¼òµ¥£¬ËùÒÔÕâÌ×ÊÓÆµ½Ì³ÌÊʺÏÐÂÊÖѧϰ¡£¸ßÊÖÒ²¿ÉÒԲο¼¿´Ï£¡
µØÖ·£ºhttp ......
PHPDocumentÊÇ´ÓÄãµÄÔ´´úÂëµÄ×¢ÊÍÖÐÉú³ÉÎĵµ£¬Òò´ËÔÚ¸øÄãµÄ³ÌÐò×ö×¢Ê͵Ĺý³Ì£¬Ò²¾ÍÊÇÄã±àÖÆÎĵµµÄ¹ý³Ì¡£
¡¡¡¡´ÓÕâÒ»µãÉϽ²£¬PHPdoc´ÙʹÄã񻄿³ÉÁ¼ºÃµÄ±à³Ìϰ¹ß£¬¾¡Á¿Ê¹Óù淶£¬ÇåÎúÎÄ×ÖΪÄãµÄ³ÌÐò×ö×¢ÊÍ£¬Í¬Ê±¶à¶àÉÙÉÙÒ²±ÜÃâÁËʺó±àÖÆÎĵµºÍÎĵµµÄ¸üв»Í¬²½µÄһЩÎÊÌâ¡£
¡¡¡¡ÔÚphpdocumentorÖУ¬×¢ÊÍ·ÖΪÎĵµÐÔ×¢ ......
<?
$_mysqlhost="localhost";
$_mysqluser="root";
$_mysqlpass="";
$_mysqldata="mydata";
$_connect=mysql_connect($_mysqlhost,$_mysqluser,$_mysqlpass) or die ("´íÎó".mysql_error());
mysql_query("SET character_set_connection=utf8, character_set_results=utf8, character_set_client=binary", $ ......