Ò׽ؽØÍ¼Èí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

PHP 5.2.11°æ±¾ÐÞ¸´¶à¸ö°²È«Â©¶´

ÊÜÓ°Ïìϵͳ£º
PHP PHP 5.2.x
²»ÊÜÓ°Ïìϵͳ£º
PHP PHP 5.2.11
ÃèÊö£º
BUGTRAQ  ID: 36449
CVE ID: CVE-2009-3291,CVE-2009-3292,CVE-2009-3293,CVE-2009-3294
PHPÊǹ㷺ʹÓõÄͨÓÃÄ¿µÄ½Å±¾ÓïÑÔ£¬ÌرðÊʺÏÓÚWeb¿ª·¢£¬¿ÉǶÈëµ½HTMLÖС£
PHPµÄ5.2.11֮ǰ°æ±¾µÄ¶à¸öº¯ÊýÖдæÔÚ°²È«Â©¶´£¬¿ÉÄÜÔÊÐíÔ¶³Ì¹¥»÷Õßµ¼Ö¾ܾø·þÎñ»òÍêÈ«ÈëÇÖÓû§ÏµÍ³¡£
1) PHPµÄphp_openssl_apply_verification_policyº¯ÊýûÓÐÕýÈ·µÄÖ´ÐÐÖ¤ÊéÑéÖ¤£¬¿ÉÄÜÔÊÐí¹¥»÷Õßͨ¹ýαÔìµÄÖ¤ÊéÖ´ÐÐÆÛÆ­¹¥»÷¡£
2) imagecolortransparentº¯ÊýûÓÐÕýÈ·µÄ¶ÔÑÕÉ«Ë÷ÒýÖ´ÐйýÂ˼ì²é¡£
3) µ±ÔËÐÐÔÚijЩWindows²Ù×÷ϵͳÉÏʱ£¬TSRM/tsrm_win32.cÎļþÖеÄpopen APIº¯ÊýÔÊÐí¹¥»÷Õßͨ¹ýµÚ¶þ¸ö²ÎÊýÖеÄÌØÖÆe»òer×Ö·û´®µ¼Ö¾ܾø·þÎñ¡£
<*À´Ô´£ºRyan Sleevi
  
  Á´½Ó£ºhttp://secunia.com/advisories/36791
        http://bugs.php.net/bug.php?id=44683
*>
²âÊÔ·½·¨£º
¾¯ ¸æ
ÒÔϳÌÐò(·½·¨)¿ÉÄÜ´øÓй¥»÷ÐÔ£¬½ö¹©°²È«Ñо¿Óë½Ìѧ֮Óá£Ê¹ÓÃÕß·çÏÕ×Ô¸º£¡
<?php
$t1 = popen("echo hello", "e");
pclose($t1);
$t2 = popen("echo hello", "re");
pclose($t2);
$t3 = popen("echo hello", "er");
pclose($t3);
?>


Ïà¹ØÎĵµ£º

PHP¿ª·¢ÍøÕ¾´úÂë±àд¹æ·¶

Ò»¡¢ ±äÁ¿ÃüÃû
a) ËùÓÐ×Öĸ¶¼Ê¹ÓÃСд
b) Ê××Öĸ¸ù¾Ý±äÁ¿ÖµÀàÐÍÖ¸¶¨
i. ÕûÊýi
ii. ¸¡µãÊýf
iii. ×Ö·û´®s
iv. ²¼¶ûÖµb
v. Êý×éa
vi. ¶ÔÏóo
vii. ×ÊÔ´r
viii. »ìºÏÀàÐÍm
c) ʹÓÃ’_’×÷Ϊÿһ¸ö´ÊµÄ·Ö½ç
ÀýÈ磺
$i_age_max = 10;
$f_price = 22.5;
$s_name =‘harry’;
$b_flag = true; ......

×Ô¼ºÐ´µÄÒ»¸öPHP·ÖÒ³Àà

Ïȸø´ó¼ÒÌùÒ»¸öʵÀý
test.php
<?php
//°üº¬seppageÀàÎļþ
require 'seppage.class.php';
//µ±Ç°Ò³Âë
$pagenow=2;
//Ò³Ãæ×ÜÊý
$pageall=10;
/*
*ÐèÒª·ÖÒ³µÄURLµØÖ·£¬¿ÉÒÔURLÖпÉÒÔ×ÔÓÉʹÓÃ?ºÅ»òÕß&ºÅ£¬³ÌÐò»á×Ô¶¯Ê¶±ð
*´Ë²ÎÊýºÍ$modurl²ÎÊýÉèÖÃÒ»Ïî¼´¿É£¬ÈôÁ½Ïî¶¼ÓУ¬Ôò°´$modurlΪ׼
*/
$url='http://l ......

PHPʵÏÖ¡¯·þÎñÆ÷ÍÆ¡¯£¨flushº¯ÊýʹÓã©

×î½üÒ»Ö±ÔÚ×ö×Ô¼ºµÄͼÊéÕ¾£¬·Ö±ðʹÓùý½ÜÆæºÍ¶Á°ÉÁ½Ìײ»Í¬µÄϵͳ£¬¶ÔÓÚÕâÁ½Ì×ϵͳҲÊÇÓÖ°®ÓÖºÞ£¬°®µÄÊÇËûÃǵŦÄÜÇ¿´ó£¬ºÞËûÃǶ¼Í¬ÊôûÓпªÔ´¾«ÉñµÄ²úÎï¡£ºÇºÇ£¬×÷ΪһÃûÇî³ÌÐòÔ±£¬°³¿ÉÒÔÀí½â×÷ÕߵĿàÖÔ£¬ÕâÀï¾Í²»ÅúÅÐÁË¡£
Äê¼ÙÆÚ¼ä£¬ÎÞÊ¿É×ö£¬·­¿´×Ô¼ºÒÔǰµÄ²É¼¯´úÂ룬·¢Ïֺܶà¿ÉÒÔÓÅ»¯ºÍÌáÉýµÄµØ·½£¬¾Í¼òµ¥×öÁËÏÂÓÅ» ......

phpѧϰ±Ê¼Ç£¨2£©

phpÅäÖÃÌ«¸´ÔÓÁË,×òÌìÍíÉÏÅäÖÃÁ˰ëÌ컹ûÓгɹ¦!²»µÃ²»Ñ°Çó¸ü¼òµ¥µÄ½â¾ö·½·¨:WampServer 5 ¼¯³É»·¾³
Wamp5ÊÇApache+PHP+Mysql ÔÚWindowsÏµļ¯³É»·¾³£¬ÓµÓмòµ¥µÄͼÐκÍ
²Ëµ¥°²×°¡£¸Ã°æ±¾¼¯³ÉÁËPHP5.2.5 Mysql5 Apache2 phpMyAdmin 2.11.2.1
SQLiteManager 1.2.0 ÂúÁ˴󲿷ÖPHPerµÄÐèÇó.
´ÓÓï·¨ÉÏ¿´£¬PHPÓïÑÔ½üËÆÓÚCÓï ......

phpÖÐpackÓëunpack

pack/unpackµÄÃþ°å×Ö·û×Ö·ûº¬Òå
format ²ÎÊýµÄ¿ÉÄÜÖµ£º
a - NUL-padded string
A - SPACE-padded string
h - Hex string, low nibble first
H - Hex string, high nibble first
c - signed char
C - unsigned char
s - signed short (always 16 bit, machine byte order)
S - unsigned short (always 16 bi ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØÍ¼ | ¸ÓICP±¸09004571ºÅ