¹ØÓÚphpÀïµÄinclude
ÔÚÒÔÇ°µÄ×öµÄÀý×ÓÖÐÓöµ½¹ýÖظ´µÄ¼ÓÔصĴíÎó ¶î ÄǸöÊÇͨ¹ýinclude_once()À´½â¾ö »òÕß²»ÈÃËûÖظ´¼ÓÔØ°ÑÖظ´µÄinclude()È¥µôÒ»¸ö»ò¶à¸ö£¬×îÖÕֻʣÏÂÒ»¸öÕâÑùÎÊÌâ¾Í½â¾öÁË£¬µ«½ñÌìÓöµ½µÄÎÊÌâ¾Í¼¬ÊÖÁË ËµÊÇÕÒ²»µ½Îļþ¡£
ÊÂÇéÊÇÕâÑùµÄ £¬½ñÌìÔÚÎļþ¼ÐÀïÔÙн¨ÁËÒ»¸öÎļþ¼Ð£¬È»ºóÒÔÇ°includeµÄÎļþ¾Í³ö»ÆÏßÁË£¬È»ºóÔÚÇ°ÃæÔÙ¼ÓÁË../»ÆÏßÏûʧ£¬²»¹ýеÄÎÊÌâ³öÏÖÁË£¡
¼ÙÉèÎÒµÄproject¹¤³ÌÀïµÄclassÎļþÓÐÕâôһ¸öclass.php¶øÆäÖÐÓÖinclude£¨../dao/userdao.php£©,¶øuserdao.phpÀïinclude(../db/db_connect.php)È»ºóÎÒÔÚclassÎļþ¼ÐÓÖн¨ÁËÒ»¸öuserÎļþ¼ÐÈ»ºó°Ñclass.php·Å½øuserÀïÍ·£¬»ÆÏß³öÏ־ͰÑclass.phpÀïµÄinclude¸Ä³Éinclude(../../dao/userdao.php),ÕýÈçÉ϶ÎËù˵£¬»ÆÏßÏûʧ£¬ÕâÏÂÌáʾ˵ÕÒ²»µ½db_connect.php ,ÎÊÌ⻹ûÓнâ¾ö£¬ÄѵÀÎҵðÑuserÎļþɾµô ÔÚproject½¨Ò»¸öuserÎļþ¼Ð£¬ÕâÑùÓ¦¸Ã»áºÃʹ£¬µ«ÓÐûÓиüºÃµÄ°ì·¨£¿»¹ÇëÖªÕ߸æËßÎÒÕâÊÇΪʲô£¬Èç¹ûÄܽ²ÏÂincludeµÄÊÇÔõô¼ÓÔصģ¬¾Í¸üºÃÁË£¬¸Ð¼¤²»¾¡£¬µÈ´ýÎÊÌâµÄ½â¾ö
Ïà¹ØÎĵµ£º
1¡¢$_SERVER['SCRIPT_NAME']¡¢$_SERVER['PHP_SELF']ºÍ$_SERVER['REQUEST_URI']Çø±ð
Àý×Ó:http://localhost/phpwind75/test.php/%22%3E%3Cscript%3Ealert(’xss’)%3C/script%3E%3Cfoo
$_SERVER['SCRIPT_NAME']Ö»»ñÈ¡½Å±¾Ãû£¬²»»ñÈ¡²ÎÊý,Êä³ö½á¹ûΪ:test.php;
$_SERVER['PHP_SELF']»ñÈ¡½Å±¾Ãûºó£¬Í¬Ê±»ñÈ ......
ÕªÒª ±¾ÎĽéÉÜPHPµÄÓŵãºÍÌØÕ÷£¬½áºÏʵÀý²ûÊöÁËPHP·ÃÎÊMySQLÊý¾Ý¿âµÄ·½·¨¡£
PHP MySQL ODBC
1. ÒýÑÔ
ÔÚInternetÓ¦ÓÃÖУ¬½«·þÎñÆ÷¶Ë½Å±¾¼¼ÊõºÍ¿Í»§¶Ë½Å±¾¼¼Êõ½áºÏÆðÀ´¿ÉÒÔÖÆ×÷³ö·á¸»¶à²ÊµÄÒ³Ãæ¡£CGIºÍASPÊDZȽÏÁ÷ÐеķþÎñÆ÷¶Ë½Å±¾¼¼Êõ¡£Í¨³£CGIÔÚ¿çƽ̨µÄ¿ª·¢ÖаçÑÝ×ÅÖ÷Òª½ÇÉ«£¬¿ÉÒÔʹÓÃVB¡¢C»òPerlµÈÀ´Ê ......
ÎÞÒâ¼ä¿´µ½ÒÔÇ°·¢µÄÌû×Ó.»ØÒäÆðÄÇЩPHPµÄÈÕÈÕÒ¹Ò¹
http://www.phpfans.net/ask/discuss2/343326196.html
<?
class gzg//¸ÆÖиÆÀà
{
var $x;//ÊôÐÔ
function gzg()//¹¹Ô캯Êý,ĬÈϲ»³Ô¸ÆÖиÆ
&n ......
±¾Ì×ÊÓƵ½Ì³ÌΪ¸ßÇåÊÓƵ½Ì³Ì£¡ÇëÈ«ÆÁ¹Û¿´£¡±¾Ì×ÊÓƵ½Ì³Ì½²µÄ±È½Ï¼òµ¥£¬Ö÷Òª½²ÁËApache·þÎñÆ÷µÄÏÂÔغͰ²×°£¬mysqlÊý¾Ý¿âµÄ¼òµ¥²Ù×÷µÈµÈ£¬»¹½²ÁËÁÄÌìÊÒÉè¼Æ
,ÁôÑÔ°å,»áÔ±¹ÜÀíϵͳ,ͶƱ¹ÜÀíϵͳ,ͼÊé¹ÜÀíϵͳ,²úÆ·½øÏú´æ¹ÜÀíϵͳ¼¸¸öʵÀý£¬¶¼±È½Ï¼òµ¥£¬ËùÒÔÕâÌ×ÊÓƵ½Ì³ÌÊʺÏÐÂÊÖѧϰ¡£¸ßÊÖÒ²¿ÉÒԲο¼¿´Ï£¡
µØÖ·£ºhttp ......
<?
$_mysqlhost="localhost";
$_mysqluser="root";
$_mysqlpass="";
$_mysqldata="mydata";
$_connect=mysql_connect($_mysqlhost,$_mysqluser,$_mysqlpass) or die ("´íÎó".mysql_error());
mysql_query("SET character_set_connection=utf8, character_set_results=utf8, character_set_client=binary", $ ......