Home > CMS Tutorial > DEDECMS > body text

What should I do if the variable coverage vulnerability in dedecms leads to an injection vulnerability?

藏色散人
Release: 2020-01-10 09:39:39
Original
2287 people have browsed it

What should I do if the variable coverage vulnerability in dedecms leads to an injection vulnerability?

What should I do if the variable coverage vulnerability of dedecms leads to an injection vulnerability?

The variable coverage vulnerability of dedecms leads to injection vulnerability

Recommended study: Dream Weaver cms

The file is: include/filter.inc. php

Defense method

/include/filter.inc.php

/**
 *  过滤不相关内容
 *
 * @access    public
 * @param     string  $fk 过滤键
 * @param     string  $svar 过滤值
 * @return    string
 */
$magic_quotes_gpc = ini_get('magic_quotes_gpc');
function _FilterAll($fk, &$svar)
{
    global $cfg_notallowstr,$cfg_replacestr;
    if( is_array($svar) )
    {
        foreach($svar as $_k => $_v)
        {
            $svar[$_k] = _FilterAll($fk,$_v);
        }
    }
    else
    {
        if($cfg_notallowstr!='' && preg_match("#".$cfg_notallowstr."#i", $svar))
        {
            ShowMsg(" $fk has not allow words!",'-1');
            exit();
        }
        if($cfg_replacestr!='')
        {
            $svar = preg_replace('/'.$cfg_replacestr.'/i', "***", $svar);
        }
    }
    if (!$magic_quotes_gpc) {
        $svar = addslashes($svar);
    }
return addslashes($svar);
//    return $svar;
}
Copy after login

The above is the detailed content of What should I do if the variable coverage vulnerability in dedecms leads to an injection vulnerability?. For more information, please follow other related articles on the PHP Chinese website!

Related labels:
source:php.cn
Statement of this Website
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn
Popular Tutorials
More>
Latest Downloads
More>
Web Effects
Website Source Code
Website Materials
Front End Template