douxue7196 2009-07-06 19:08
浏览 6

安全动态包含

I been using this php dynamic include code on my site. But I think it not safe, how can write safer and better code to replace this:

$page = (empty($_GET['page'])) ? '' : $_GET['page'].".html";

if (empty($page))
{ 
 $page = 'index.html';
}

else
 {
 $page = $page;

 }

 include($page);

Thank you very much

  • 写回答

6条回答 默认 最新

  • douxing5199 2009-07-06 19:12
    关注

    You can define some sort of whitelist to determine what files are allowed to be included in this fashion and check that list before doing the include.

    Another way would be to only allow includes within a certain directory (or child directories) and verify that the requested files are within that directory.

    评论

报告相同问题?

悬赏问题

  • ¥17 pro*C预编译“闪回查询”报错SCN不能识别
  • ¥15 微信会员卡接入微信支付商户号收款
  • ¥15 如何获取烟草零售终端数据
  • ¥15 数学建模招标中位数问题
  • ¥15 phython路径名过长报错 不知道什么问题
  • ¥15 深度学习中模型转换该怎么实现
  • ¥15 HLs设计手写数字识别程序编译通不过
  • ¥15 Stata外部命令安装问题求帮助!
  • ¥15 从键盘随机输入A-H中的一串字符串,用七段数码管方法进行绘制。提交代码及运行截图。
  • ¥15 TYPCE母转母,插入认方向