1. 程式人生 > >ecshop SQL注入漏洞導致程式碼執行

ecshop SQL注入漏洞導致程式碼執行

139c139,140
+       $arr['num'] = intval($arr['num']);
+       $arr['id'] = intval($arr['id']);
267c268
---
270c271,272
+       $arr['id'] = intval($arr['id']);
+       $arr['type'] = addslashes($arr['type']);
308c310
---
+       $arr['id'] = intval($arr['id']);