dedecms注入漏洞(edit.inc.php)

文件:edit.inc.php

路径:.../plus/guestbook/edit.inc.php

解决方案

查找文件位置:/plus/guestbook/edit.inc.php  ,大概在55行左右,找到:

$dsql->ExecuteNoneQuery("UPDATE `dede_guestbook` SET `msg`='$msg', `posttime`='".time()."' WHERE id='$id' ");

修改为:

$msg = addslashes($msg); $dsql->ExecuteNoneQuery("UPDATE `dede_guestbook` SET `msg`='$msg', `posttime`='".time()."' WHERE id='$id' ");

猜你喜欢

转载自blog.csdn.net/L_melody/article/details/86549890