语句的缺没有加引号,本来addslashes防止sql注入的原理就是转义’ “ %00这些有特殊含义的符号,防止它逃出引号,但是这里没有加引号,所以可以直接构造任意sql语句了,无视过滤
?...= $db->fetch_array($result))
{
if (empty($row['companyname']))
{
continue;
}
$row['addtime']=date("Y-m-d...'in_content' => $text,
'in_isread' => 0,
'in_addtime' => date('Y-m-d...2565%2565%2570%2528%2535%2529%2520%2561%256e%2564%2520%2527%2531%2527%253d%2527%2531&uname=aaa
因为这里是从$...(about,content,face,username,ip,sendtime)values('$about','$content','$face','$user','$ip','".date('Y-m-d