dongqing904999 2009-08-27 16:22
浏览 18

文件存在安全吗?

if (file_exists("pages/$page.php")) {
  include($page.'.php');
}

Is this safe?

With Safe i mean that you cant include remote scripts etc

  • 写回答

6条回答 默认 最新

  • douiwn6941 2009-08-27 16:25
    关注

    The code you posted has a typo i believe. It should be:

    if (file_exists("pages/$page.php")) {
      include("pages/$page.php");
    }
    

    It however leads to code injection, if PHP settings allow it, remote file inclusion.

    You need to make sure the page that you include can not be any arbitrary page.

    Usually you'll see this type of code in a "Loader" class employing the Factory Method, however, in good implementations it restricts the files and classes it will load to a certain directory, or to a certain predefined set of files.

    评论

报告相同问题?

悬赏问题

  • ¥15 这种微信登录授权 谁可以做啊
  • ¥15 请问我该如何添加自己的数据去运行蚁群算法代码
  • ¥20 用HslCommunication 连接欧姆龙 plc有时会连接失败。报异常为“未知错误”
  • ¥15 网络设备配置与管理这个该怎么弄
  • ¥20 机器学习能否像多层线性模型一样处理嵌套数据
  • ¥20 西门子S7-Graph,S7-300,梯形图
  • ¥50 用易语言http 访问不了网页
  • ¥50 safari浏览器fetch提交数据后数据丢失问题
  • ¥15 matlab不知道怎么改,求解答!!
  • ¥15 永磁直线电机的电流环pi调不出来