drhanjuw56233 2010-05-24 23:07
浏览 46
已采纳

有人可以在我的库中执行php函数但是没有在查看的页面上调用吗?

Let's say I have a php file, test.php with 2 functions: test1() and test2().

If I have an external php file, index.php, with include(test.php) in its code. If in the index.php file has a reference to test1() but not test2(), is there any way that someone would be able to execute test2() by doing something malicious while using the index.php file?

  • 写回答

2条回答 默认 最新

  • dongta5747 2010-05-24 23:38
    关注

    The only way they could execute arbitrary code is through a code injection vulnerability.

    Here's an oversimplified example:

    <?php
    
    $runthis = $_GET["runthis"];
    
    $runthis();
    

    So an attacker could invoke your script as http://example.com/index.php?runthis=test2 and then it would run your test2() function.

    Read more about code injection at the wikipedia article I linked to above, or at the OWASP site.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论
查看更多回答(1条)

报告相同问题?

悬赏问题

  • ¥15 下图接收小电路,谁知道原理
  • ¥15 装 pytorch 的时候出了好多问题,遇到这种情况怎么处理?
  • ¥20 IOS游览器某宝手机网页版自动立即购买JavaScript脚本
  • ¥15 手机接入宽带网线,如何释放宽带全部速度
  • ¥30 关于#r语言#的问题:如何对R语言中mfgarch包中构建的garch-midas模型进行样本内长期波动率预测和样本外长期波动率预测
  • ¥15 ETLCloud 处理json多层级问题
  • ¥15 matlab中使用gurobi时报错
  • ¥15 这个主板怎么能扩出一两个sata口
  • ¥15 不是,这到底错哪儿了😭
  • ¥15 2020长安杯与连接网探