Ò׽ؽØÍ¼Èí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

PHP 5.2.11°æ±¾ÐÞ¸´¶à¸ö°²È«Â©¶´

ÊÜÓ°Ïìϵͳ£º
PHP PHP 5.2.x
²»ÊÜÓ°Ïìϵͳ£º
PHP PHP 5.2.11
ÃèÊö£º
BUGTRAQ  ID: 36449
CVE ID: CVE-2009-3291,CVE-2009-3292,CVE-2009-3293,CVE-2009-3294
PHPÊǹ㷺ʹÓõÄͨÓÃÄ¿µÄ½Å±¾ÓïÑÔ£¬ÌرðÊʺÏÓÚWeb¿ª·¢£¬¿ÉǶÈëµ½HTMLÖС£
PHPµÄ5.2.11֮ǰ°æ±¾µÄ¶à¸öº¯ÊýÖдæÔÚ°²È«Â©¶´£¬¿ÉÄÜÔÊÐíÔ¶³Ì¹¥»÷Õßµ¼Ö¾ܾø·þÎñ»òÍêÈ«ÈëÇÖÓû§ÏµÍ³¡£
1) PHPµÄphp_openssl_apply_verification_policyº¯ÊýûÓÐÕýÈ·µÄÖ´ÐÐÖ¤ÊéÑéÖ¤£¬¿ÉÄÜÔÊÐí¹¥»÷Õßͨ¹ýαÔìµÄÖ¤ÊéÖ´ÐÐÆÛÆ­¹¥»÷¡£
2) imagecolortransparentº¯ÊýûÓÐÕýÈ·µÄ¶ÔÑÕÉ«Ë÷ÒýÖ´ÐйýÂ˼ì²é¡£
3) µ±ÔËÐÐÔÚijЩWindows²Ù×÷ϵͳÉÏʱ£¬TSRM/tsrm_win32.cÎļþÖеÄpopen APIº¯ÊýÔÊÐí¹¥»÷Õßͨ¹ýµÚ¶þ¸ö²ÎÊýÖеÄÌØÖÆe»òer×Ö·û´®µ¼Ö¾ܾø·þÎñ¡£
<*À´Ô´£ºRyan Sleevi
  
  Á´½Ó£ºhttp://secunia.com/advisories/36791
        http://bugs.php.net/bug.php?id=44683
*>
²âÊÔ·½·¨£º
¾¯ ¸æ
ÒÔϳÌÐò(·½·¨)¿ÉÄÜ´øÓй¥»÷ÐÔ£¬½ö¹©°²È«Ñо¿Óë½Ìѧ֮Óá£Ê¹ÓÃÕß·çÏÕ×Ô¸º£¡
<?php
$t1 = popen("echo hello", "e");
pclose($t1);
$t2 = popen("echo hello", "re");
pclose($t2);
$t3 = popen("echo hello", "er");
pclose($t3);
?>


Ïà¹ØÎĵµ£º

php jquery Ajax Ìá½»¡¢¶ÁÈ¡ json

<mce:script type="text/javascript" language="javascript"><!--
function del(com_id,meet_id){
$.ajax({
url:'../company/meet.Ajax.php',
type:'POST',
data:{com_id:com_id,meet_id:meet_id},
dataType:"json",
timeout: 10 ......

ʲôÊÇPHPÀàºÍÀàµÄ¶ÔÏó(PHPµÄÀà¼ò½é)

 
ÀࣨClass£©£ºÊÇһЩ±äÁ¿ÓëһЩʹÓÃÕâЩ±äÁ¿µÄº¯ÊýµÄ¼¯ºÏ¡£
¿É¼òµ¥Àí½âΪº¯ÊýºÍ±äÁ¿µÄ¼¯ºÏ£¬»ò±äÁ¿ºÍº¯ÊýµÄ¶¨ÒåµÄ¼¯ºÏ¡£
Óï·¨ÊÇ£º
class Class_name //ϰ¹ßÉÏÀàµÄµÚÒ»¸ö×Ö·ûΪ´óд£¬²¢ÇÒ±ØÐë·ûºÏ±äÁ¿µÄÃüÃû¹æÔò¡£
{
//º¯ÊýÓë±äÁ¿µÄ¼¯ºÏ(һЩ±äÁ¿(Àà³ÉÔ±)ºÍº¯Êý(ÐÐΪ·½·¨)µÄ¶¨Òå)¡£
}
Êý¾Ý³ÉÔ±(±äÁ¿)ÔÚÀ ......

php¶àÏß³ÌÉÏÏÂÎÄÖа²È«Ð´Îļþ

Ìṩһ¸öphp¶àÏß³ÌÉÏÏÂÎÄÖа²È«Ð´ÎļþµÄʵÏÖ·½·¨¡£Õâ¸öʵÏÖûÓÐʹÓÃphp µÄfile lock»úÖÆ£¬Ê¹ÓõÄÊÇÁÙʱÎļþ»úÖÆ¡£¶àÏß³ÌÖеĸ÷¸öÏ̶߳¼ÊǶԸ÷×Ô£¨Ã¿¸öÏ̶߳ÀÕ¼Ò»¸ö£©µÄÁÙʱÎļþд£¬È»ºóÔÙͬ²½µ½Ô­ÎļþÖС£
<?php
/**
* @usage: used to offer safe file write operation in multiple threads context, arbitory file ......

phpαÔìÀ´Â·Ò³Ãæ

<?php
$host = "www.abc.com"; //ÄãÒª·ÃÎʵÄÓòÃû
$target = "/test.asp"; //ÄãÒª·ÃÎʵÄÒ³ÃæµØÖ·
$referer = "http://www.abcdefg.com/abc.html"; //αÔìÀ´Â·Ò³Ãæ
$fp = fsockopen($host, 80, $errno, $errstr, 30);
if (!$fp){
echo "$errstr($errno)<br />\n";
} ......

PHPʵÏÖ¡¯·þÎñÆ÷ÍÆ¡¯£¨flushº¯ÊýʹÓã©

×î½üÒ»Ö±ÔÚ×ö×Ô¼ºµÄͼÊéÕ¾£¬·Ö±ðʹÓùý½ÜÆæºÍ¶Á°ÉÁ½Ìײ»Í¬µÄϵͳ£¬¶ÔÓÚÕâÁ½Ì×ϵͳҲÊÇÓÖ°®ÓÖºÞ£¬°®µÄÊÇËûÃǵŦÄÜÇ¿´ó£¬ºÞËûÃǶ¼Í¬ÊôûÓпªÔ´¾«ÉñµÄ²úÎï¡£ºÇºÇ£¬×÷ΪһÃûÇî³ÌÐòÔ±£¬°³¿ÉÒÔÀí½â×÷ÕߵĿàÖÔ£¬ÕâÀï¾Í²»ÅúÅÐÁË¡£
Äê¼ÙÆÚ¼ä£¬ÎÞÊ¿É×ö£¬·­¿´×Ô¼ºÒÔǰµÄ²É¼¯´úÂ룬·¢Ïֺܶà¿ÉÒÔÓÅ»¯ºÍÌáÉýµÄµØ·½£¬¾Í¼òµ¥×öÁËÏÂÓÅ» ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØÍ¼ | ¸ÓICP±¸09004571ºÅ