Ò׽ؽØͼÈí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

PHP 5.2.11°æ±¾ÐÞ¸´¶à¸ö°²È«Â©¶´

ÊÜÓ°Ïìϵͳ£º
PHP PHP 5.2.x
²»ÊÜÓ°Ïìϵͳ£º
PHP PHP 5.2.11
ÃèÊö£º
BUGTRAQ  ID: 36449
CVE ID: CVE-2009-3291,CVE-2009-3292,CVE-2009-3293,CVE-2009-3294
PHPÊǹ㷺ʹÓõÄͨÓÃÄ¿µÄ½Å±¾ÓïÑÔ£¬ÌرðÊʺÏÓÚWeb¿ª·¢£¬¿ÉǶÈëµ½HTMLÖС£
PHPµÄ5.2.11֮ǰ°æ±¾µÄ¶à¸öº¯ÊýÖдæÔÚ°²È«Â©¶´£¬¿ÉÄÜÔÊÐíÔ¶³Ì¹¥»÷Õßµ¼Ö¾ܾø·þÎñ»òÍêÈ«ÈëÇÖÓû§ÏµÍ³¡£
1) PHPµÄphp_openssl_apply_verification_policyº¯ÊýûÓÐÕýÈ·µÄÖ´ÐÐÖ¤ÊéÑéÖ¤£¬¿ÉÄÜÔÊÐí¹¥»÷Õßͨ¹ýαÔìµÄÖ¤ÊéÖ´ÐÐÆÛÆ­¹¥»÷¡£
2) imagecolortransparentº¯ÊýûÓÐÕýÈ·µÄ¶ÔÑÕÉ«Ë÷ÒýÖ´ÐйýÂ˼ì²é¡£
3) µ±ÔËÐÐÔÚijЩWindows²Ù×÷ϵͳÉÏʱ£¬TSRM/tsrm_win32.cÎļþÖеÄpopen APIº¯ÊýÔÊÐí¹¥»÷Õßͨ¹ýµÚ¶þ¸ö²ÎÊýÖеÄÌØÖÆe»òer×Ö·û´®µ¼Ö¾ܾø·þÎñ¡£
<*À´Ô´£ºRyan Sleevi
  
  Á´½Ó£ºhttp://secunia.com/advisories/36791
        http://bugs.php.net/bug.php?id=44683
*>
²âÊÔ·½·¨£º
¾¯ ¸æ
ÒÔϳÌÐò(·½·¨)¿ÉÄÜ´øÓй¥»÷ÐÔ£¬½ö¹©°²È«Ñо¿Óë½Ìѧ֮Óá£Ê¹ÓÃÕß·çÏÕ×Ô¸º£¡
<?php
$t1 = popen("echo hello", "e");
pclose($t1);
$t2 = popen("echo hello", "re");
pclose($t2);
$t3 = popen("echo hello", "er");
pclose($t3);
?>


Ïà¹ØÎĵµ£º

PHPÀàµÄÊôÐÔ·ÃÎÊÆ÷·½·¨

µ±´æÈ¡Ò»¸öÀàµÄ²»´æÔÚµÄÊôÐÔʱ£¬½âÎöÆ÷»áÅжÏÊÇ·ñÓÐÒÔÏÂÁ½¸öÊôÐÔ·ÃÎÊÆ÷·½·¨£º
__getºÍ__set¡£
Èç¹ûÓУ¬Ôò»á×Ô¶¯µ÷ÓÃÕâЩ·½·¨¡£Í¨¹ýÊôÐÔ·ÃÎÊÆ÷·½·¨¿ÉÒÔ¿ØÖƶÔÀàÊôÐԵķÃÎÊ£¬ÒÔʵÏÖ¶ÔÒª±£´æµÄÊý¾Ý½øÐмì²é£¬´Ó¶øÈ·±£ÊôÐÔÖµÓÐÒâÒåµÄÊý¾Ý¡£__get·½·¨Ö»ÓÐÒ»¸ö²ÎÊý£¬ÓÃÓÚ´«µÝÊôÐÔµÄÃû³Æ¡£__set·½·¨ÓÐÁ½¸ö²ÎÊý£¬·Ö±ðÓÃÓÚ´«µÝÊôÐÔ ......

phpÖÐheaderº¯ÊýµÄʹÓÃ

header("HTTP/1.0 400 Bad Request");¡¡·µ»Ø400´íÎó
header("HTTP/1.0 404 Not Found"); ·µ»Ø404´íÎó
header("Location:http://$host$uri/$extra"); Ìøת
//ÉèÖÃnocache¡¡£¬¹ýÆÚ
header
(
"Cache-Control: no-cache,
must-revalidate"
);
//
HTTP/1.1
header
(
&q ......

×Ô¼ºÐ´µÄÒ»¸öPHP·ÖÒ³Àà

Ïȸø´ó¼ÒÌùÒ»¸öʵÀý
test.php
<?php
//°üº¬seppageÀàÎļþ
require 'seppage.class.php';
//µ±Ç°Ò³Âë
$pagenow=2;
//Ò³Ãæ×ÜÊý
$pageall=10;
/*
*ÐèÒª·ÖÒ³µÄURLµØÖ·£¬¿ÉÒÔURLÖпÉÒÔ×ÔÓÉʹÓÃ?ºÅ»òÕß&ºÅ£¬³ÌÐò»á×Ô¶¯Ê¶±ð
*´Ë²ÎÊýºÍ$modurl²ÎÊýÉèÖÃÒ»Ïî¼´¿É£¬ÈôÁ½ÏÓУ¬Ôò°´$modurlΪ׼
*/
$url='http://l ......

PHPһЩÓÐÒâ˼µÄСÇø±ð

µ¥ÒýºÅ'ºÍË«ÒýºÅ"µÄÇø±ð£º

Ê×ÏÈÊǵ¥ÒýºÅÒª±ÈË«ÒýºÅÖ´ÐÐЧÂÊÒª¸ß£¬ÒòΪ˫ÒýºÅ»á¶ÔÄÚÈݽøÐÐÔ¤´¦Àí¡£
ÀýÈ磺'$value' Êä³ö×Ö·û $value ; "$value"Êä³ö±äÁ¿$valueµÄÖµ¡£
charºÍvarcharµÄÇø±ð£º

charÊǶ¨³¤¶øvarcharÊDZ䳤£¬charµÄÖ÷ÒªÌصãÊÇ´æ´¢·½Ê½Ô¤·ÖÅ䣬varcharµ±ËüµÄÊý¾Ý³¤¶È·¢Éú±ä»¯Ê±»áÓ ......

phpÓëÊý¾Ý¿â

PHPer
Ϊʲô±»ÈÏΪÊDzݸù£¿
                        —— Ò»¸öÖµµÃPHPer˼¿¼µÄÎÊÌâ
¿ªÆª×¢ÊÍ£ºÒÔÏÂÎÄ×Ö²¢Ã»Óзdz£¶àµÄ¼¼Êõ´Ê»ã£¬ËùÒÔÖ»Òª¶Ô
PHP
¸ÐÐËȤµÄÈ˶¼¿ÉÒÔ¿´¿´¡£
PHPe ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØͼ | ¸ÓICP±¸09004571ºÅ