function brule() { global $dv,$db,$boardid,$lang,$groupboardid; $groupboardid=$_GET['groupboardid']; if(!empty($_GET['groupboardid'])){ $rules=$db->scalar("select rules from {$dv}group_board where id={$groupboardid}"); } else{ $rules=$db->scalar("select rules from {$dv}board where boardid={$boardid}"); } 直接获得变量groupboardid,不为空就直接带入查询导致注入。 dvbbs PHP版 暂无
function brule() { global $dv,$db,$boardid,$lang,$groupboardid; $groupboardid=$_GET['groupboardid']; if(!empty($_GET['groupboardid'])){ $rules=$db->scalar("select rules from {$dv}group_board where id={$groupboardid}"); } else{ $rules=$db->scalar("select rules from {$dv}board where boardid={$boardid}"); } 直接获得变量groupboardid,不为空就直接带入查询导致注入。 dvbbs PHP版 暂无