Ò׽ؽØÍ¼Èí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

phpѧϰ±Ê¼Ç

 1¡¢$_SERVER['SCRIPT_NAME']¡¢$_SERVER['PHP_SELF']ºÍ$_SERVER['REQUEST_URI']Çø±ð
Àý×Ó:http://localhost/phpwind75/test.php/%22%3E%3Cscript%3Ealert(’xss’)%3C/script%3E%3Cfoo
$_SERVER['SCRIPT_NAME']Ö»»ñÈ¡½Å±¾Ãû£¬²»»ñÈ¡²ÎÊý,Êä³ö½á¹ûΪ:test.php;
$_SERVER['PHP_SELF']»ñÈ¡½Å±¾Ãûºó£¬Í¬Ê±»ñÈ¡²ÎÊýÊý¾Ý£¬²¢¶Ô²ÎÊýÊý¾Ý½øÐÐÒ»´Îurldecode²Ù×÷£¬Ò׳öÏÖ¿çÕ¾¹¥»÷ÏÖÏó,Êä³ö½á¹ûΪ:
"><script>alert('xss')</script><foo
$_SERVER['REQUEST_URI']»ñÈ¡½Å±¾Ãûºó£¬Í¬Ê±»ñÈ¡²ÎÊýԭʼÊý¾Ý,²Ù×÷½á¹ûΪ£º
test.php/%22%3E%3Cscript%3Ealert(’xss’)%3C/script%3E%3Cfoo
2¡¢urldecodeÓërawurldecodeÇø±ð
urldecode½«"+"½âÎöΪ" ",¶ørawurldecodeÔò²»½âÎö
3¡¢&&Óë||ÓÅÏȼ¶ÎÊÌâ
&&¼¶±ð±È||¸ß
4¡¢È«¾Ö±äÁ¿ÎÊÌâ
Èç¹ûÔÚͬһ¸öÎļþÄÚ$a= $_GLOBALS[a];
ÔÚº¯ÊýÖÐÈç¹ûÒªÒýÓÃÈ«¾Ö±äÁ¿Ôò±ØÐë:global $a;·ñÔòÖ»ÊÇ˽ÓбäÁ¿
ÀýÈ磺
global $a;
$a=2;
function test(){
echo $a;
}
test();

Õâ¸ö½á¹û½«Îª¿Õ
¶ø
global $a;
$a=2;

function test(){
global $a;
echo $a;
}

test();

Õâ¸ö½á¹û½«Îª:2,
Èç¹ûʹÓÃ$_GLOBALS[a]µÄ»°£¬Ôò½á¹ûҲΪ2:
global $a;
$a=2;

function test(){
echo $GLOBALS[a];
}

test();


Ïà¹ØÎĵµ£º

phpÃæÊÔ£¨±ÊÊÔ²¿·Ö£©

 
ÆÕͨPHP³ÌÐòÔ±±ÊÊÔÌâ
1. ÓÃPHP´òÓ¡³öǰһÌìµÄʱ¼ä£¬´òÓ¡¸ñʽÊÇ2007Äê5ÔÂ10ÈÕ 22:21:21
2. PHP´úÂëÈçÏ£º
$a="hello"; 
$b=&$a;
unset($b);
$b="world"; 
echo $a;
Æä½á¹ûÊÇ£¿
3. PHP´úÂëÈçÏ£º
$str="cd"; 
  $$str="landog";  
$$st ......

09Äê5ÔÂ11ºÅ×îÐÂPHPÃæÊÔÌâ

һѡÔñÌ⣺
1.ÏÂÃæµÄÄǸöÑ¡Ïî¿ÉÒÔ»ñÈ¡±íµ¥Ìá½»µÄÖµ£¿£¨¶àÑ¡£© b d
<form name='frm1' method="post">
<input type="text" name="name" ><input type="submit" name="a">
</form>
A.$_GET['name']
B.$_POST['name']
C.$_SESSION['name']
D.$_REQUEST['name']
E.$_GLOBAL['name']
2.ÍüÀ²¡£ ......

ÓÃphp¹ýÂË±íµ¥Ìá½»ÖеÄΣÏÕhtml´úÂë

ÓÃPHP¹ýÂËÌá½»±íµ¥µÄhtml´úÂëÀï¿ÉÄÜÓб»ÀûÓÃÒýÈëÍⲿΣÏÕÄÚÈݵĴúÂë¡£ÀýÈ磬ÓÐЩʱºòÓû§Ìá½»±íµ¥Öк¬ÓÐhtmlÄÚÈÝ£¬µ«Õâ¿ÉÄÜÔì³ÉÏÔÊ¾Ò³Ãæ²¼¾Ö»ìÂÒ£¬ÐèÒª¹ýÂ˵ô¡£
ÒÔÏÂÊdzÌÐò´úÂ룺
¸´ÖÆ´úÂë
function uhtml($str) 

    $farr = array( 
    ......

PHPʵÏÖÔ²½ÇͼƬ

¹¤×÷ÖÐÓõ½£¬×Ô¼ºÐ´ÁËÒ»¸ö£¬·ÖÏí¸øÓÐÐèÒªµÄÈË£¬Ç°ÃæÊÇÀඨÒ壬ºóÃæ2ÐÐÊǵ÷Óá£
Óŵ㣺
²»ÐèÒªÍⲿͼƬ
Ö§³ÖPNG͸Ã÷
¿É×Ô¶¨ÒåÔ²½Ç°ë¾¶
²»×㣺
Ö»ÄÜÖ¸¶¨Ò»ÖÖ͸Ã÷É«
 <?php
class RoundedCorner {
private $_r;
private $_g;
private $_b;
private $_image_path;
private $_radius;

function _ ......

PHP: global static ºÍ$GLOBALS$ʹÓÃÓëÇø±ð

1.globalÔÚÕû¸öÒ³ÃæÆð×÷Óá£
2.staticÖ»ÔÚfunctionºÍclassÄÚÆð×÷Óá£
globalºÍ$GLOBALSʹÓûù±¾Ïàͬ£¬µ«ÔÚʵ¼Ê¿ª·¢Öдó²»Ïàͬ¡£
globalÔÚº¯Êý²úÉúÒ»¸öÖ¸Ïòº¯ÊýÍⲿ±äÁ¿µÄ±ðÃû±äÁ¿£¬¶ø²»ÊÇÕæÕýµÄº¯ÊýÍⲿ±äÁ¿£¬Ò»µ«¸Ä±äÁ˱ðÃû±äÁ¿µÄÖ¸ÏòµØÖ·£¬¾Í»á·¢ÉúһЩÒâÁϲ»µ½Çé¿ö£¬ÀýÈçÀý×Ó1.
$GLOBALS[]ȷȷʵʵµ÷ÓÃÊÇÍⲿµÄ±äÁ¿£ ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØÍ¼ | ¸ÓICP±¸09004571ºÅ