dedecms注入漏洞(edit.inc.php
文件:edit.inc.php
路径:…/plus/guestbook/edit.inc.php
路径:…/plus/guestbook/edit.inc.php
解决方案:
查找文件位置:/plus/guestbook/edit.inc.php ,大概在55行左右,找到:
$dsql->ExecuteNoneQuery(“UPDATE `dede_guestbook` SET `msg`=’$msg’, `posttime`='”.time().”‘ WHERE id=’$i
修改为:
$msg = addslashes($msg); $dsql->ExecuteNoneQuery(“UPDATE `dede_guestbook` SET `msg`=’$msg’, `posttime`='”.time().”‘ WHERE id=’$id’ “);
原文链接:https://blog.csdn.net/L_melody/article/details/86549890