Browse Source

修正存在的注入问题

tags/6.1.0^2
tianya 3 years ago
parent
commit
d97c45bdd8
3 changed files with 9 additions and 1 deletions
  1. +4
    -0
      src/admin/sys_info.php
  2. +4
    -0
      src/system/database/dedesqli.class.php
  3. +1
    -1
      src/system/database/dedesqlite.class.php

+ 4
- 0
src/admin/sys_info.php View File

@@ -32,6 +32,7 @@ function ReWriteConfig()
if ($row['value'] == '') $row['value'] = 0;
fwrite($fp, "\${$row['varname']} = ".$row['value'].";\r\n");
} else {
$row['value'] = stripslashes($row['value']);
fwrite($fp, "\${$row['varname']} = '".str_replace("'", '', $row['value'])."';\r\n");
}
}
@@ -49,6 +50,9 @@ if ($dopost == "save") {
continue;
}
$k = preg_replace("#^edit___#", "", $k);
$v = $dsql->Esc($v);
$k = $dsql->Esc($k);
$dsql->ExecuteNoneQuery("UPDATE `#@__sysconfig` SET `value`='$v' WHERE varname='$k' ");
}
ReWriteConfig();


+ 4
- 0
src/system/database/dedesqli.class.php View File

@@ -189,6 +189,10 @@ class DedeSqli
function Esc($_str)
{
global $dsqli;
if (!$dsqli->isInit) {
$this->Init($this->pconnect);
}
if (version_compare(phpversion(), '4.3.0', '>=')) {
return @mysqli_real_escape_string($this->linkID, $_str);
} else {


+ 1
- 1
src/system/database/dedesqlite.class.php View File

@@ -163,7 +163,7 @@ class DedeSqlite
function Esc($_str)
{
return addslashes($_str);
return $this->linkID->escapeString($_str);
}
//执行一个不返回结果的SQL语句,如update,delete,insert等


Loading…
Cancel
Save